{"id":"e3e27d4c-d128-4767-8979-447d61be6306","entityType":"agent","slug":"clawhub-mebusw-zoom-meeting-admin","name":"zoom-meeting-admin","canonicalUrl":"https://www.xpersona.co/agent/clawhub-mebusw-zoom-meeting-admin","canonicalPath":"/agent/clawhub-mebusw-zoom-meeting-admin","generatedAt":"2026-10-10T11:52:50.409Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T09:47:59.817Z","emptyReason":null},"description":"List, create, delete, and query Zoom meetings, cloud recordings, and account users via a fixed CLI (scripts/zoom-s2s.py, 7 whitelisted actions) using Server-to-Server OAuth. Use when the user asks to schedule, reschedule, cancel, find, or look up a Zoom meeting; set up a recurring Zoom; pull cloud recordings or past meeting metadata; or look up account users. Triggers on phrases like \"Zoom meeting\", \"zoom 会议\", \"约 Zoom\", \"取消 Zoom\", \"录像\", \"schedule a Zoom\", \"cancel the meeting\", \"who's on the call\", \"云录制\". create_meeting requires explicit confirmation of topic, start_time, duration; delete_meeting requires --yes and visible confirmation. Agent must only invoke the 7 whitelisted CLI actions and must not modify the script, import internals, or call Zoom REST directly. Requires .env with ACCOUNT_ID/CLIENT_ID/CLIENT_SECRET/USER_ID. Documentation is in Chinese; outputs follow.","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.5K downloads reported by the source. Last updated 10/10/2026.","installCommand":"clawhub skill install s17fqnnawywqwp37410y5w9r1h83pwab:zoom-meeting-admin","sourceUrl":"https://clawhub.ai/mebusw/zoom-meeting-admin","homepage":"https://clawhub.ai/mebusw/skills/zoom-meeting-admin","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/mebusw/zoom-meeting-admin","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/mebusw/skills/zoom-meeting-admin","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":64,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"zoom-meeting-admin technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-10T09:47:59.817Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T09:47:59.817Z","emptyReason":null},"stars":null,"forks":null,"downloads":1515,"packageName":null,"latestVersion":"1.0.6","tractionLabel":"1.5K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T09:47:59.817Z","emptyReason":null},"lastUpdatedAt":"2026-10-10T09:47:59.817Z","lastCrawledAt":"2026-10-10T09:47:59.817Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-11T09:47:59.817Z","lastVerifiedAt":null,"highlights":[{"version":"1.0.6","createdAt":"2026-09-27T02:51:10.935Z","changelog":"zoom-meeting-admin v1.0.6 - Simplified and clarified agent documentation in SKILL.md; usage notes moved and refocused. - Updated allowed tool list: Bash invocation now limited to \"python3 zoom-s2s.py\" from within scripts/ directory. - Out-of-scope functionality and response handling guidance are now explicitly documented. - Removed deprecated scripts and the skill-card.md file for a cleaner repo. - Skill trigger guidance and example agent outputs improved for clarity and precision.","fileCount":8,"zipByteSize":16342},{"version":"1.0.5","createdAt":"2026-08-18T09:28:01.893Z","changelog":"zoom-meeting-admin 1.0.5 - Strengthened security documentation and clarified over-permission boundaries; agents are now explicitly prohibited from importing internal functions, modifying the script, or calling arbitrary Zoom API endpoints. - Enhanced SKILL.md with detailed warnings and examples about Zoom recurrence parameters, especially clarifying Zoom weekday encoding (1=Sunday). - Updated CLI usage section with correct positional parameters for recurring meetings and new reference examples for monthly recurrences. - Improved .gitignore and README files for consistency and reinforced credential file handling precautions. - Removed obsolete skill-card.md file.","fileCount":9,"zipByteSize":15705},{"version":"1.0.4","createdAt":"2026-08-13T12:22:30.781Z","changelog":"zoom-meeting-admin 1.0.4 - Added CLI support for creating recurring (周期性) Zoom meetings via extra create_meeting arguments. - Updated SKILL.md with detailed documentation and CLI examples for recurring meetings. - Provided a .env.sample template and .gitignore for credentials management. - Removed outdated skill-card.md. - Improved guidance on parameter passing for recurring meetings, emphasizing string use for weekly_days.","fileCount":9,"zipByteSize":13005},{"version":"1.0.3","createdAt":"2026-06-05T14:11:00.160Z","changelog":"- Renamed skill to \"zoom-meeting-admin\" and updated all naming for clarity and consistency. - Added a detailed Permissions & Security section, clarifying tool usage, credential storage, scope limits, and explicit action whitelisting. - Strengthened documentation on credential security practices and recommended standalone OAuth app usage. - Clarified that only a fixed set of meeting/user/recording operations are supported; arbitrary API calls are now explicitly forbidden. - Removed the redundant \"skill-card.md\" file.","fileCount":6,"zipByteSize":11375},{"version":"1.0.2","createdAt":"2026-05-20T03:46:16.227Z","changelog":"- Added detailed documentation for creating recurring (type=8) Zoom meetings, including correct usage of the recurrence parameter. - Provided clarification and code examples for the `weekly_days` field, emphasizing that it must be a string (not an array) to avoid API errors. - Expanded the \"踩坑记录\" (troubleshooting notes) section with a new tip regarding `weekly_days` as a string to prevent common mistakes.","fileCount":6,"zipByteSize":9938},{"version":"1.0.1","createdAt":"2026-05-05T06:36:13.625Z","changelog":"- Added .env and .env.sample files to provide environment configuration templates. - Updated documentation with enhanced guidance on minimum permission scopes and safety requirements for API use. - Command for deleting meetings now requires --yes for confirmation. - Adjusted trigger words in description for broader matching. - Introduced explicit agent operation protocols emphasizing user confirmation and restricting action scope.","fileCount":5,"zipByteSize":8002},{"version":"1.0.0","createdAt":"2026-05-04T13:57:39.575Z","changelog":"Initial release with updated REST API integration and simplified script usage. - Replaced all previous API code with a single, no-dependency Python script (zoom-s2s.py) for core Zoom meeting operations. - Credentials configuration now uses a .env file for easier setup and management. - Added multi-language documentation: both English and simplified Chinese README included. - Removed old API reference and script files for a cleaner project structure. - Token handling is now automatic and cached for improved usability and reliability. - Expanded usage: added support for listing users and querying cloud recordings, alongside meeting management.","fileCount":5,"zipByteSize":7378}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17fqnnawywqwp37410y5w9r1h83pwab:zoom-meeting-admin","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s17fqnnawywqwp37410y5w9r1h83pwab:zoom-meeting-admin` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/mebusw/zoom-meeting-admin before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-mebusw-zoom-meeting-admin/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-mebusw-zoom-meeting-admin/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-mebusw-zoom-meeting-admin/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-mebusw-zoom-meeting-admin/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-mebusw-zoom-meeting-admin/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-mebusw-zoom-meeting-admin/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T11:52:50.407Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-mebusw-zoom-meeting-admin/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-mebusw-zoom-meeting-admin/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-mebusw-zoom-meeting-admin/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-mebusw-zoom-meeting-admin/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T09:47:59.817Z","emptyReason":null},"readme":"Skill: zoom-meeting-admin\n\nOwner: mebusw\n\nSummary: List, create, delete, and query Zoom meetings, cloud recordings, and account users via a fixed CLI (scripts/zoom-s2s.py, 7 whitelisted actions) using Server-to-Server OAuth. Use when the user asks to schedule, reschedule, cancel, find, or look up a Zoom meeting; set up a recurring Zoom; pull cloud recordings or past meeting metadata; or look up account users. Triggers on phrases like \"Zoom meeting\", \"zoom 会议\", \"约 Zoom\", \"取消 Zoom\", \"录像\", \"schedule a Zoom\", \"cancel the meeting\", \"who's on the call\", \"云录制\". create_meeting requires explicit confirmation of topic, start_time, duration; delete_meeting requires --yes and visible confirmation. Agent must only invoke the 7 whitelisted CLI actions and must not modify the script, import internals, or call Zoom REST directly. Requires .env with ACCOUNT_ID/CLIENT_ID/CLIENT_SECRET/USER_ID. Documentation is in Chinese; outputs follow.\n\nTags: latest:1.0.6\n\nVersion history:\n\nv1.0.6 | 2026-09-27T02:51:10.935Z | auto\n\nzoom-meeting-admin v1.0.6\n\n- Simplified and clarified agent documentation in SKILL.md; usage notes moved and refocused.\n- Updated allowed tool list: Bash invocation now limited to \"python3 zoom-s2s.py\" from within scripts/ directory.\n- Out-of-scope functionality and response handling guidance are now explicitly documented.\n- Removed deprecated scripts and the skill-card.md file for a cleaner repo.\n- Skill trigger guidance and example agent outputs improved for clarity and precision.\n\nv1.0.5 | 2026-08-18T09:28:01.893Z | auto\n\nzoom-meeting-admin 1.0.5\n\n- Strengthened security documentation and clarified over-permission boundaries; agents are now explicitly prohibited from importing internal functions, modifying the script, or calling arbitrary Zoom API endpoints.\n- Enhanced SKILL.md with detailed warnings and examples about Zoom recurrence parameters, especially clarifying Zoom weekday encoding (1=Sunday).\n- Updated CLI usage section with correct positional parameters for recurring meetings and new reference examples for monthly recurrences.\n- Improved .gitignore and README files for consistency and reinforced credential file handling precautions.\n- Removed obsolete skill-card.md file.\n\nv1.0.4 | 2026-08-13T12:22:30.781Z | auto\n\nzoom-meeting-admin 1.0.4\n\n- Added CLI support for creating recurring (周期性) Zoom meetings via extra create_meeting arguments.\n- Updated SKILL.md with detailed documentation and CLI examples for recurring meetings.\n- Provided a .env.sample template and .gitignore for credentials management.\n- Removed outdated skill-card.md.\n- Improved guidance on parameter passing for recurring meetings, emphasizing string use for weekly_days.\n\nv1.0.3 | 2026-06-05T14:11:00.160Z | user\n\n- Renamed skill to \"zoom-meeting-admin\" and updated all naming for clarity and consistency.\n- Added a detailed Permissions & Security section, clarifying tool usage, credential storage, scope limits, and explicit action whitelisting.\n- Strengthened documentation on credential security practices and recommended standalone OAuth app usage.\n- Clarified that only a fixed set of meeting/user/recording operations are supported; arbitrary API calls are now explicitly forbidden.\n- Removed the redundant \"skill-card.md\" file.\n\nv1.0.2 | 2026-05-20T03:46:16.227Z | user\n\n- Added detailed documentation for creating recurring (type=8) Zoom meetings, including correct usage of the recurrence parameter.\n- Provided clarification and code examples for the `weekly_days` field, emphasizing that it must be a string (not an array) to avoid API errors.\n- Expanded the \"踩坑记录\" (troubleshooting notes) section with a new tip regarding `weekly_days` as a string to prevent common mistakes.\n\nv1.0.1 | 2026-05-05T06:36:13.625Z | user\n\n- Added .env and .env.sample files to provide environment configuration templates.\n- Updated documentation with enhanced guidance on minimum permission scopes and safety requirements for API use.\n- Command for deleting meetings now requires --yes for confirmation.\n- Adjusted trigger words in description for broader matching.\n- Introduced explicit agent operation protocols emphasizing user confirmation and restricting action scope.\n\nv1.0.0 | 2026-05-04T13:57:39.575Z | user\n\nInitial release with updated REST API integration and simplified script usage.\n\n- Replaced all previous API code with a single, no-dependency Python script (zoom-s2s.py) for core Zoom meeting operations.\n- Credentials configuration now uses a .env file for easier setup and management.\n- Added multi-language documentation: both English and simplified Chinese README included.\n- Removed old API reference and script files for a cleaner project structure.\n- Token handling is now automatic and cached for improved usability and reliability.\n- Expanded usage: added support for listing users and querying cloud recordings, alongside meeting management.\n\nArchive index:\n\nArchive v1.0.6: 8 files, 16342 bytes\n\nFiles: .env.sample (744b), .gitignore (32b), README.md (3402b), README.zh-cn.md (3417b), scripts/zoom-s2s.py (12983b), skill-card.md (2131b), SKILL.md (14664b), _meta.json (137b)\n\nFile v1.0.6:SKILL.md\n\n---\nname: zoom-meeting-admin\nallowed-tools: Bash(python3 zoom-s2s.py:*) Read\ncompatibility: Requires Python 3.7+; performs HTTPS calls to zoom.us and api.zoom.us (network); writes a token cache to ~/.zoom-s2s-token.json (auto chmod 600); reads ZOOM_ACCOUNT_ID / ZOOM_CLIENT_ID / ZOOM_CLIENT_SECRET / ZOOM_USER_ID from a local .env.\ndescription: List, create, delete, and query Zoom meetings, cloud recordings, and account users via a fixed CLI (scripts/zoom-s2s.py, 7 whitelisted actions) using Server-to-Server OAuth. Use when the user asks to schedule, reschedule, cancel, find, or look up a Zoom meeting; set up a recurring Zoom; pull cloud recordings or past meeting metadata; or look up account users. Triggers on phrases like \"Zoom meeting\", \"zoom 会议\", \"约 Zoom\", \"取消 Zoom\", \"录像\", \"schedule a Zoom\", \"cancel the meeting\", \"who's on the call\", \"云录制\". create_meeting requires explicit confirmation of topic, start_time, duration; delete_meeting requires --yes and visible confirmation. Agent must only invoke the 7 whitelisted CLI actions and must not modify the script, import internals, or call Zoom REST directly. Requires .env with ACCOUNT_ID/CLIENT_ID/CLIENT_SECRET/USER_ID. Documentation is in Chinese; outputs follow.\n---\n\n> ⚠️ **安全提示 — 凭证等同于账户管理员口令**\n>\n> 本 Skill 通过 `.env` 中的 `ZOOM_CLIENT_SECRET` 等 Server-to-Server OAuth 凭证访问 Zoom 账户。\n> `ACCOUNT_ID + CLIENT_ID + CLIENT_SECRET` 三元组可换取 1 小时有效的账户级访问令牌，**能够读取该账户下所有会议元数据、云录像，并执行删除等破坏性操作**。\n>\n> **使用前请先完整阅读 [`## 凭证安全`](#凭证安全)**，遵守 `.gitignore`、`chmod 600`、最小 scope、专用 App、泄露应急等要求。\n> 任何**修改脚本、import 内部函数、构造任意 payload 调用 `api_call`** 的尝试都构成越权，会被本文档明确禁止。\n\n# Zoom Server-to-Server OAuth REST API\n\n## 权限与约束\n\n本 Skill 通过 `scripts/zoom-s2s.py` 调用 Zoom Server-to-Server OAuth REST API，不实现\"通用 REST 代理\"。\n\n- **声明的工具**：`Bash(python3 zoom-s2s.py:*)`（仅执行本 skill 的 CLI 脚本）、`Read`（读取 SKILL.md、脚本源码、`.env.sample`、token cache 等）。\n- **网络访问**：向 `https://zoom.us/oauth/token` 与 `https://api.zoom.us/v2/*` 发起 HTTPS 请求，传输头包含 `Authorization: Bearer <token>`。\n- **文件写入**：在 `~/.zoom-s2s-token.json` 缓存访问令牌（已自动 `chmod 600`）。\n- **凭证读取**：从仓库根目录的 `.env` 读取 `ZOOM_ACCOUNT_ID` / `ZOOM_CLIENT_ID` / `ZOOM_CLIENT_SECRET` / `ZOOM_USER_ID`。\n- **允许的 Action（白名单）**——禁止构造任意 Zoom REST 请求或调用未列出的端点：\n  - 会议：`list_meetings` / `get_meeting` / `create_meeting` / `delete_meeting`\n  - 用户：`get_user` / `list_users`\n  - 录像：`recordings`\n- **越权防护**：脚本内部包含一个 `api_call` 函数供 CLI action 复用，但这是**私有实现细节，不是对外可调用的接口**。Agent 不得通过以下任何方式旁路调用白名单外的 Zoom 端点（如 `DELETE /users/{id}`、`PATCH /accounts/{id}` 等高风险端点）：\n  - 修改 `scripts/zoom-s2s.py`、新增 CLI action、暴露 `api_call`；\n  - `from zoom_s2s import api_call` 或以其他方式直接调用脚本内部函数；\n  - 在调用本 Skill 的同时**另起进程**用相同凭证调任意 Zoom REST API（如 `curl` 直接打 `api.zoom.us`）；\n  - 注入参数、拼接 URL、构造任意 JSON payload 绕过 CLI 校验逻辑。\n  脚本遵循\"最小暴露面\"原则：CLI 只暴露 7 个白名单 action，**任何其他调用路径都视为越权**。\n- **强人类确认**：`create_meeting` 与 `delete_meeting` 在执行前必须获得用户显式确认；`delete_meeting` 命令还需附加 `--yes` 参数。\n\n## 凭证配置\n\n在 `.env` 文件中配置（**仅 chmod 600，不要提交到任何 Git 仓库**）：\n\n```env\nZOOM_ACCOUNT_ID=你的AccountID\nZOOM_CLIENT_ID=你的ClientID\nZOOM_CLIENT_SECRET=你的ClientSecret\nZOOM_USER_ID=你的用户邮箱或user_id\n```\n\n> ⚠️ 完整的安全规范见下一节 `## 凭证安全`。\n\n**Token 获取方式**：Server-to-Server OAuth，机器对机器，无需用户交互授权。\n\n## 凭证安全\n\n`.env` 中的 `ZOOM_CLIENT_SECRET` 是长期有效的账户级凭据，等同于账户管理员口令。**必须**遵守：\n\n- **加入 `.gitignore`**：本仓库 `.gitignore` 已包含 `.env`；同步确保 IDE、备份工具、文件同步（iCloud / Dropbox / OneDrive / 坚果云）不会自动上传该文件。\n- **限制文件权限**：`chmod 600 .env`；`scripts/zoom-s2s.py` 缓存的 `~/.zoom-s2s-token.json` 同样敏感（已自动 `chmod 600`），**不要**复制到剪贴板、聊天窗口、终端截图、报错工单、AI 对话上下文或第三方日志服务。\n- **不要在共享环境复用**：CI runner、公用跳板机、容器镜像、共享开发机中复用同一份凭据 ≈ 凭据公开。`Account ID + Client ID + Client Secret` 三元组可换得 1 小时有效的访问令牌。\n- **最小权限**：按 `## 最小权限配置建议` 表按需开启 Scope；不需要的 Action 不要勾选对应权限；`delete_meeting` 之外的写权限（`meeting:write:update`、`user:write:*`、`account:write:*`）默认不要开。\n- **独立 App**：为此 Skill 单独创建一个 Zoom Server-to-Server App，**不要**复用其他业务 App 的凭据；一旦泄露，旋转该 App 的凭据即可，不影响其他业务。\n- **凭据泄露应急**：在 Zoom Marketplace 删除该 App → 重新创建并轮换 `ACCOUNT_ID` / `CLIENT_ID` / `CLIENT_SECRET` / `USER_ID` 四项 → `rm -f ~/.zoom-s2s-token.json` 强制下次重新认证 → 复盘泄露路径。\n\n## Out of scope（不在本 Skill 范围内）\n\n下列能力**不在**本 Skill 范围内；Agent 不应通过旁路调用 `api_call` 或 `curl` 等方式实现：\n\n- Zoom **Webinar**（与 Meeting 是不同产品，API 不同，需 `webinar:*` scope）\n- 注册表单、参会者注册管理、邮件 invite\n- Zoom Phone / Zoom Chat / Zoom Whiteboard\n- 会议期间的实时控制（mute / unmute / recording start-stop）\n- 账户/账单/SSO 配置\n- Chat 消息发送（`chat_message` 端点）\n\n如需以上能力，请走 Zoom Web UI 或 Marketplace 上的专用 App。\n\n## 核心脚本\n\n`scripts/zoom-s2s.py` — 纯 Python，无外部依赖，兼容 Python 3.7+。\n\n```bash\n# 调用前先 cd 到 scripts/ 目录（skill 根目录下的 scripts/ 子目录）\ncd scripts\n\n# 获取帮助\npython3 zoom-s2s.py help\n\n# 列出即将到来的会议\npython3 zoom-s2s.py list_meetings <user> <page_size> upcoming\n\n# 获取单个会议详情\npython3 zoom-s2s.py get_meeting <meeting_id>\n\n# 创建会议 (start_time: YYYY-MM-DDTHH:MM:SS)\npython3 zoom-s2s.py create_meeting \"<主题>\" \"<start_time>\" <时长分钟> [时区] [密码]\n# 创建周期性会议（每周一，7次，每次120分钟；weekly_days=\"2\" = Zoom 编码周一）\npython3 zoom-s2s.py create_meeting \"CSM公开课\" \"2026-05-23T08:00:00\" 120 Asia/Shanghai \"\" 2 1 2 7\npython3 zoom-s2s.py create_meeting \"煎饼果子讨论会\" \"2026-05-05T10:00:00\" 60 Asia/Shanghai\n\n# 删除会议\npython3 zoom-s2s.py delete_meeting <meeting_id>\n\n# 获取云录像\npython3 zoom-s2s.py recordings <user> <page_size>\n\n# 获取用户信息\npython3 zoom-s2s.py get_user [user]\n\n# 列出账户下所有用户\npython3 zoom-s2s.py list_users [page_size]\n```\n\n### 典型响应\n\n`create_meeting` 成功返回（节选）：\n\n```json\n{\n  \"id\": 85123456789,\n  \"topic\": \"每周一的产品同步\",\n  \"type\": 2,\n  \"start_time\": \"2026-08-24T20:00:00Z\",\n  \"duration\": 120,\n  \"timezone\": \"America/New_York\",\n  \"join_url\": \"https://us05web.zoom.us/j/85123456789?pwd=...\",\n  \"start_url\": \"https://us05web.zoom.us/s/85123456789?zak=...\",\n  \"password\": \"abc123\"\n}\n```\n\n**Agent 应当**：\n- 把 `join_url` 展示给用户（这是参会者链接）。\n- 把 `id`（meeting_id）记下来备用。\n- **不要**展示 `start_url`（这是主持人链接，含 host key 摘要，泄露后他人可代为启动会议）。\n\n`list_meetings` 返回 `{meetings: [...], page_count, total_records}`；`recordings` 返回 `{recording_files: [...], ...}`。\n\n## Token 缓存\n\n脚本自动缓存 Token 到 `~/.zoom-s2s-token.json`（有效期约 50 分钟），重复调用无需每次重新认证。\n\n## 常用操作快速参考\n\n| 操作 | 命令 |\n|------|------|\n| 列出最近5个会议 | `list_meetings <user> 5 upcoming` |\n| 列出最近10个历史会议 | `list_meetings <user> 10 past` |\n| 创建明天10点会议 | `create_meeting \"主题\" \"YYYY-MM-DDT10:00:00\" 60 Asia/Shanghai` |\n| 创建周期性会议（每周一） | `create_meeting \"主题\" \"YYYY-MM-DDT20:00:00\" 120 America/New_York \"\" 2 1 2 7` |\n| 创建月度会议（每月15号） | `create_meeting \"主题\" \"YYYY-MM-15T10:00:00\" 60 Asia/Shanghai \"\" 3 1 15 12` |\n| 创建月度会议（第N个周二） | `create_meeting \"主题\" \"...\" 60 ... \"\" 3 1 3 6 \"\" \"\" 2` |\n| 获取会议详情 | `get_meeting <id>` |\n| 删除会议 | `delete_meeting <id> --yes` |\n| 获取云录像 | `recordings <user> 10` |\n\n## 最小权限配置建议\n\n根据实际使用场景按需开通 scope，不需要的功能不要授权：\n\n| 功能 | 所需 Scope | 建议 |\n|------|-----------|------|\n| 列出会议 | `meeting:read:list_meetings` | ✅ 核心 |\n| 查看会议详情 | `meeting:read:meeting` | ✅ 核心 |\n| 创建会议 | `meeting:write:create` | 按需开启 |\n| **删除会议** | `meeting:write:delete` | ⚠️ 谨慎开启 |\n| **读取云录像** | `cloud_recording:read:list_user_recordings` | ⚠️ 谨慎开启 |\n| **列出账户用户** | `user:read:list_users` | ⚠️ 谨慎开启 |\n\n> 建议为此 Skill 单独创建一个 Zoom Server-to-Server App，不要复用已有 App 的凭证。\n\n## Agent 调用规范\n\n- **创建会议前**：向用户确认主题、时间、时长，再执行。\n- **删除会议前**：必须向用户明确展示会议信息并获得确认，命令需附加 `--yes` 参数。\n- **禁止超范围调用**：仅允许文档中列出的 Action，不得构造任意 Zoom REST API 请求。\n\n## 执行后验证\n\n- **create_meeting**：执行后展示返回的 `join_url` / `id` 给用户；记录 meeting_id 备用。\n- **delete_meeting**：执行后立刻 `list_meetings <user> upcoming` 验证会议已消失，并向用户报告\"已删除 meeting_id=...\"。\n- **任何失败**：展示原始错误（含 HTTP code + Zoom error message），**不要**把 Client Secret、access_token 或 `start_url` 写入日志/截图/对话上下文。\n\n## 创建周期性会议\n\n`create_meeting` 通过位置参数直接支持周期性会议（**无需绕过 CLI**）：\n\n```bash\npython3 zoom-s2s.py create_meeting \"<主题>\" \"<start_time>\" <duration> [timezone] [password] \\\n  [recurrence_type] [repeat_interval] [weekly_days] [end_times] [end_date_time] \\\n  [monthly_day] [monthly_weeks]\n```\n\n| 参数 | 适用 type | 说明 | 示例 |\n|------|----------|------|------|\n| `recurrence_type` | 全部 | 1=每日, 2=每周, 3=每月 | `2` |\n| `repeat_interval` | 全部 | 每几周/天/月重复 | `1` |\n| `weekly_days` | type=2, type=3+monthly_weeks | 周几字符串（Zoom 编码：**1=周日, 2=周一, 3=周二, ..., 7=周六**）| `\"2\"` = 周一, `\"3,5\"` = 周二+周四 |\n| `end_times` | 全部 | 总共几次 | `7` |\n| `end_date_time` | 全部 | 结束日期（二选一）| `\"2026-10-06T00:00:00Z\"` |\n| `monthly_day` | type=3 | 每月第几天字符串（1-31，单值或逗号分隔）| `\"15\"` 或 `\"1,15\"` |\n| `monthly_weeks` | type=3 | 每月第几个周次（-1=最后, 1-4），配合 `weekly_days` | `2` |\n\n> ⚠️ **重要：`weekly_days` 是 Zoom 编码，不是 ISO 编码。** 1=周日（不是周一）。常见误用：\n> - 想约周一 → `weekly_days=\"2\"`（不是 `\"1\"`）\n> - 想约周六 → `weekly_days=\"7\"`（不是 `\"6\"`）\n> - 想约周日 → `weekly_days=\"1\"`\n\n### 示例：每周一 20:00（EDT），共 7 次，每次 2 小时\n```bash\npython3 zoom-s2s.py create_meeting \"每周一的产品同步\" \\\n  \"2026-08-24T20:00:00\" 120 America/New_York \"\" 2 1 2 7\n# weekly_days=\"2\" = Zoom 编码 2 = 周一\n```\n\n### 示例：每月 15 号 10:00，共 12 次\n```bash\npython3 zoom-s2s.py create_meeting \"月度复盘\" \\\n  \"2026-08-15T10:00:00\" 60 Asia/Shanghai \"\" 3 1 15 12\n# positional: topic, start_time, duration, tz, password, type=3, repeat=1, weekly_days=15, end_times=12\n# 解释: monthly_day=\"15\"（每月 15 号）\n```\n\n### 示例：每月第 2 个周二 20:00，共 6 次\n```bash\npython3 zoom-s2s.py create_meeting \"月度董事会\" \\\n  \"2026-08-25T20:00:00\" 60 America/New_York \"\" 3 1 3 6 \"\" \"\" 2\n# positional: ..., type=3, repeat=1, weekly_days=\"3\", end_times=6, end_date_time=\"\", monthly_day=\"\", monthly_weeks=2\n# 解释: monthly_weeks=2 + weekly_days=\"3\" = 每月第 2 个周二（Zoom 编码 3 = 周二）\n```\n\n**⚠️ 关键避坑：`weekly_days` / `monthly_day` 必须是字符串，不是数组！**\n\n| 错误写法 | 正确写法 |\n|---------|---------|\n| `\"weekly_days\": [6]` | `\"weekly_days\": \"6\"`（单日） |\n| `\"weekly_days\": [\"6\"]` | `\"weekly_days\": \"6\"` |\n|  | `\"weekly_days\": \"6,7\"`（多日，**周五+周六**——Zoom 编码） |\n|  | `\"weekly_days\": \"2,3,5\"`（**周一+周二+周四**——Zoom 编码） |\n|  | `\"weekly_days\": \"1,7\"`（**周日+周六**——Zoom 编码两端） |\n| `\"monthly_day\": [15]` | `\"monthly_day\": \"15\"` |\n|  | `\"monthly_day\": \"1,15\"`（每月 1 号和 15 号） |\n\n`weekly_days` Zoom 编码：1=周日，2=周一，3=周二，4=周三，5=周四，6=周五，7=周六。\n\n## 踩坑记录\n\n1. **scope 错误 (4711)**：某些 API（如 `get_user`）需要在 App 里开通对应 scope，又如 `list_meetings` 需要在 App 里开通 `meeting:read:list_meetings` 权限\n2. **Token 有效期**：Server-to-Server Token 有效期 1 小时，脚本自动刷新并缓存\n3. **用户 ID**：可用邮箱，也可用 `list_users` 查 user_id\n4. **`weekly_days` / `monthly_day` 必须为字符串**：Zoom API 要求 `weekly_days`、`monthly_day` 是 `\"6\"` / `\"15\"` 这样的字符串，而非 `[6]` / `[15]` 数组，传数组会报 300 错误（CLI 已自动 `str()`，但调用方传入时仍需注意）。`weekly_days` 是 Zoom 编码（1=周日, 2=周一, ..., 7=周六），不是 ISO 编码。\n5. **月度循环的两种写法**：`monthly_day` 表示\"每月第几天\"，`monthly_weeks + weekly_days` 表示\"每月第几个周几\"。两者二选一，不要同时给；同时给会让 Zoom 拒绝（300 错误）\n\nFile v1.0.6:README.md\n\n# SKILL of Zoom Server-to-Server OAuth REST API\n\nManage and schedule Zoom meetings REST API directly via Server-to-Server OAuth — no VPS required, no MCP protocol needed.\n\n> EN | [中文](README.zh-cn.md)\n\n## Setup Steps\n\n1. Log in to https://marketplace.zoom.us/\n2. From the \"Develop\" dropdown, select \"build app\" and create an app of type `Server-to-Server OAuth`\n3. Add required OAuth Scopes\n4. Get the credentials\n5. Activate the app\n6. Invoke this SKILL in your AI agent\n\n## Credentials\n\n> ⚠️ **The `ZOOM_CLIENT_SECRET` in `.env` is equivalent to an account-admin password.** Anyone holding the `ACCOUNT_ID + CLIENT_ID + CLIENT_SECRET` triple can mint a 1-hour account-level access token that reads all meeting metadata, cloud recordings, and can delete meetings.\n>\n> - Never commit `.env` to git. Confirm your IDE, backup tools, and file-sync services (iCloud / Dropbox / OneDrive / Nutstore) are not auto-uploading it.\n> - `chmod 600 .env`. The token cache at `~/.zoom-s2s-token.json` is auto-set to `chmod 600` by the script.\n> - Use the **minimum scopes** you actually need (see table below). Do not enable `meeting:write:delete`, `cloud_recording:read:*`, or `user:read:list_users` unless required.\n> - Create a **dedicated** Server-to-Server App for this skill — do not reuse credentials from other business apps.\n> - If leaked: delete the App in Zoom Marketplace → re-create and rotate all four values → `rm -f ~/.zoom-s2s-token.json`.\n\nEdit the `.env` file with your Zoom Server-to-Server OAuth App credentials:\n\n```env\nZOOM_ACCOUNT_ID=yourAccountID\nZOOM_CLIENT_ID=yourClientID\nZOOM_CLIENT_SECRET=yourClientSecret\nZOOM_USER_ID=your_user_email_or_user_id\n```\n\n\n## Required OAuth Scopes\n\nEnable these in your Zoom Marketplace Server-to-Server OAuth App:\n\n| Scope | Purpose |\n|-------|---------|\n| `meeting:read:list_meetings` | List meetings |\n| `meeting:write:create` | Create meetings |\n| `meeting:write:delete` | Delete meetings |\n| `cloud_recording:read:list_user_recordings` | View cloud recordings |\n| `user:read:list_users` | List users |\n| `user:read:user` | Get user info |\n\n## Quick Start\n\n```bash\ncd ~/.agents/skills/zoom-s2s-oauth/scripts\n\n# List upcoming meetings\npython3 zoom-s2s.py list_meetings service@uperform.cn 5 upcoming\n\n# Create a meeting (start_time format: YYYY-MM-DDTHH:MM:SS)\npython3 zoom-s2s.py create_meeting \"Pancake Discussion\" \"2026-05-05T10:00:00\" 60 Asia/Shanghai\n\n# Get cloud recordings\npython3 zoom-s2s.py recordings service@uperform.cn 10\n```\n\n## Directory Structure\n\n```\nzoom-s2s-oauth/\n├── SKILL.md           # AI Agent invocation guide\n├── README.md          # This file\n├── README.zh-cn.md    # 中文版\n├── .env               # Credentials (do NOT commit to git!)\n└── scripts/\n    └── zoom-s2s.py    # Main script (pure Python3, no external dependencies)\n```\n\n\n## Comparison: MCP vs Server-to-Server REST\n\n| | MCP | Server-to-Server REST |\n|---|---|---|\n| Requires VPS | ✅ Yes (OAuth callback) | ❌ No |\n| Protocol | MCP (JSON-RPC) | Standard REST (pure Python, no deps) |\n| Token | User-Managed OAuth | Server-to-Server OAuth |\n| Complexity | High (proxy+OAuth) | Low (direct call) |\n| Features | Zoom MCP tools | 7 whitelisted CLI actions (list/get/create/delete meeting, get/list user, list recordings) |\n\nIf you only need core Zoom meeting/recording features, Server-to-Server REST is simpler.\n\nFile v1.0.6:_meta.json\n\n{\n  \"ownerId\": \"kn75w6500mvryv9p0k3czdfww982r5xh\",\n  \"slug\": \"zoom-meeting-admin\",\n  \"version\": \"1.0.6\",\n  \"publishedAt\": 1790477470935\n}\n\nFile v1.0.6:README.zh-cn.md\n\n# SKILL of Zoom Server-to-Server OAuth REST API \n\n用 Server-to-Server OAuth 直接调 Zoom meeting REST API，不需要 VPS，不需要 MCP 协议，管理和安排ZOOM会议。\n\n> [EN](README.md) | 中文\n\n## 配置步骤\n\n1. 需要先手动登录 https://marketplace.zoom.us/\n2. 在 \"Develop\" 下拉菜单选 \"build app\", 创建一个 `Server-to-Server OAuth`类型的APP\n3. 添加必要的OAuth Scope。\n4. 获取相关凭证密码\n5. 激活APP\n6. 在AI agent中调用此 SKILL\n\n## 凭证配置\n\n> ⚠️ **`.env` 中的 `ZOOM_CLIENT_SECRET` 等同于账户管理员口令。** 持有 `ACCOUNT_ID + CLIENT_ID + CLIENT_SECRET` 三元组即可换取 1 小时有效的账户级访问令牌，**能读取该账户下所有会议元数据、云录像，并执行删除等破坏性操作**。\n>\n> - 千万不要把 `.env` 提交到 git。确认你的 IDE、备份工具、文件同步服务（iCloud / Dropbox / OneDrive / 坚果云）没有自动上传该文件。\n> - `chmod 600 .env`。脚本缓存的 token 文件 `~/.zoom-s2s-token.json` 由脚本自动 `chmod 600`。\n> - **按需开通最小 scope**（见下表）。未用到的功能不要勾选对应权限；不要轻易开启 `meeting:write:delete`、`cloud_recording:read:*`、`user:read:list_users`。\n> - 为本 Skill **单独创建一个** Server-to-Server App，不要复用其他业务 App 的凭据。\n> - 一旦泄露：在 Zoom Marketplace 删除该 App → 重新创建并轮换四项值 → `rm -f ~/.zoom-s2s-token.json` 强制重新认证。\n\n编辑 `.env` 文件，填入你的 Zoom Server-to-Server OAuth App 凭证：\n\n```env\nZOOM_ACCOUNT_ID=你的AccountID\nZOOM_CLIENT_ID=你的ClientID\nZOOM_CLIENT_SECRET=你的ClientSecret\nZOOM_USER_ID=你的用户邮箱或user_id\n```\n\n\n## 需要的 OAuth Scope\n\n在 Zoom Marketplace 你的 Server-to-Server OAuth App 里开通：\n\n| Scope | 用途 |\n|-------|------|\n| `meeting:read:list_meetings` | 列出会议 |\n| `meeting:write:create` | 创建会议 |\n| `meeting:write:delete` | 删除会议 |\n| `cloud_recording:read:list_user_recordings` | 查看云录像 |\n| `user:read:list_users` | 列出用户 |\n| `user:read:user` | 获取用户信息 |\n\n## 快速开始\n\n```bash\ncd ~/.agents/skills/zoom-s2s-oauth/scripts\n\n# 列出最近5个会议\npython3 zoom-s2s.py list_meetings service@uperform.cn 5 upcoming\n\n# 创建会议 (start_time 格式: YYYY-MM-DDTHH:MM:SS)\npython3 zoom-s2s.py create_meeting \"煎饼果子讨论会\" \"2026-05-05T10:00:00\" 60 Asia/Shanghai\n\n# 获取云录像\npython3 zoom-s2s.py recordings service@uperform.cn 10\n```\n\n## 目录结构\n\n```\nzoom-s2s-oauth/\n├── SKILL.md           # AI Agent 调用说明\n├── README.md          # 本文件\n├── .env               # 凭证配置 (不要提交到 git!)\n└── scripts/\n    └── zoom-s2s.py    # 主脚本 (纯 Python3，无外部依赖)\n```\n\n\n## 对比：MCP vs Server-to-Server REST\n\n| | MCP 方式 | Server-to-Server REST |\n|---|---|---|\n| 需要 VPS | ✅ 需要 (OAuth 回调) | ❌ 不需要 |\n| 协议 | MCP (JSON-RPC) | 标准 REST (Python 无外部依赖) |\n| Token | User-Managed OAuth | Server-to-Server OAuth |\n| 复杂度 | 高 (代理+OAuth) | 低 (直接调) |\n| 功能 | Zoom MCP 工具集 | 7 个白名单 CLI action（list/get/create/delete meeting、get/list user、list recordings） |\n\n如果你只需要调用 Zoom 会议/录像等核心功能，Server-to-Server REST 方式更简单。\n\nFile v1.0.6:skill-card.md\n\n## Description:\n\nHelps agents manage Zoom meetings and look up account users and cloud recordings through seven approved Server-to-Server OAuth actions.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[mebusw](https://clawhub.ai/user/mebusw)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nZoom account administrators and their agents use this skill to schedule, find, and cancel meetings, retrieve cloud recording information, and look up account users.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Account-level credentials and cached access tokens could expose meeting and recording data.\n\nMitigation: Use a dedicated Zoom app, keep .env and token files private and out of repositories and sync tools, and avoid shared machines.\n\nRisk: Unnecessary Zoom permissions could enable deletion or access to sensitive recordings.\n\nMitigation: Grant only the required OAuth scopes; leave deletion and recording access disabled unless needed.\n\nRisk: Meeting deletion is irreversible and meeting host links are sensitive.\n\nMitigation: Require explicit confirmation before creating or deleting meetings, use --yes only after confirming deletion, and share attendee links rather than host links.\n\n## Reference(s):\n\n- [Source repository](https://github.com/mebusw/zoom-meeting-admin)\n- [ClawHub skill release](https://clawhub.ai/mebusw/skills/zoom-meeting-admin)\n- [Zoom App Marketplace](https://marketplace.zoom.us/)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Shell commands, Guidance]\n\n**Output Format:** [Markdown with meeting details and links]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May include meeting IDs, attendee links, user details, and recording information; never disclose credentials or host links.]\n\n## Skill Version(s):\n\n1.0.6 (source: ClawHub release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.0.5: 9 files, 15705 bytes\n\nFiles: .env.sample (744b), .gitignore (32b), README.md (3402b), README.zh-cn.md (3417b), scripts (0b), scripts/zoom-s2s.py (12983b), skill-card.md (2310b), SKILL.md (12950b), _meta.json (137b)\n\nFile v1.0.5:SKILL.md\n\n---\nname: zoom-meeting-admin\nallowed-tools: Bash(python3:*) Bash(ls:*) Bash(cat:*) Read\ncompatibility: Requires Python 3.7+, network access to zoom.us and api.zoom.us, and a local .env with Zoom Server-to-Server OAuth credentials.\ndescription: Manage Zoom meetings, cloud recordings, and account users via a Server-to-Server OAuth REST script. Use this skill when the user wants to list, view, create, or delete a scheduled Zoom meeting; query cloud recordings for a user; or look up account users. The script exposes a fixed CLI action whitelist (list/get/create/delete meeting, get/list user, list recordings); agents must only invoke these documented actions and must not modify the script, import internal functions, or construct arbitrary Zoom API requests. create_meeting requires the agent to obtain explicit user confirmation of topic, start_time, and duration before invoking. delete_meeting is gated by a required --yes flag and the agent must display the meeting info and obtain explicit user confirmation before invoking. Requires a Zoom Server-to-Server OAuth app and a local .env with ACCOUNT_ID, CLIENT_ID, CLIENT_SECRET, USER_ID.\n---\n\n> ⚠️ **安全提示 — 凭证等同于账户管理员口令**\n>\n> 本 Skill 通过 `.env` 中的 `ZOOM_CLIENT_SECRET` 等 Server-to-Server OAuth 凭证访问 Zoom 账户。\n> `ACCOUNT_ID + CLIENT_ID + CLIENT_SECRET` 三元组可换取 1 小时有效的账户级访问令牌，**能够读取该账户下所有会议元数据、云录像，并执行删除等破坏性操作**。\n>\n> **使用前请先完整阅读 [`## 凭证安全`](#凭证安全)**，遵守 `.gitignore`、`chmod 600`、最小 scope、专用 App、泄露应急等要求。\n> 任何**修改脚本、import 内部函数、构造任意 payload 调用 `api_call`** 的尝试都构成越权，会被本文档明确禁止。\n\n# Zoom Server-to-Server OAuth REST API\n\n## 权限与约束\n\n本 Skill 通过 `scripts/zoom-s2s.py` 调用 Zoom Server-to-Server OAuth REST API，不实现\"通用 REST 代理\"。\n\n- **声明的工具**：`Bash(python3:*)`（执行 `scripts/zoom-s2s.py`）、`Bash(ls:*)` / `Bash(cat:*)`（查看脚本输出与缓存）、`Read`（读取凭证文件与文档）。\n- **网络访问**：向 `https://zoom.us/oauth/token` 与 `https://api.zoom.us/v2/*` 发起 HTTPS 请求，传输头包含 `Authorization: Bearer <token>`。\n- **文件写入**：在 `~/.zoom-s2s-token.json` 缓存访问令牌（已自动 `chmod 600`）。\n- **凭证读取**：从仓库根目录的 `.env` 读取 `ZOOM_ACCOUNT_ID` / `ZOOM_CLIENT_ID` / `ZOOM_CLIENT_SECRET` / `ZOOM_USER_ID`。\n- **允许的 Action（白名单）**——禁止构造任意 Zoom REST 请求或调用未列出的端点：\n  - 会议：`list_meetings` / `get_meeting` / `create_meeting` / `delete_meeting`\n  - 用户：`get_user` / `list_users`\n  - 录像：`recordings`\n- **越权防护**：脚本内部包含一个 `api_call` 函数供 CLI action 复用，但这是**私有实现细节，不是对外可调用的接口**。Agent 不得通过以下任何方式旁路调用白名单外的 Zoom 端点（如 `DELETE /users/{id}`、`PATCH /accounts/{id}` 等高风险端点）：\n  - 修改 `scripts/zoom-s2s.py`、新增 CLI action、暴露 `api_call`；\n  - `from zoom_s2s import api_call` 或以其他方式直接调用脚本内部函数；\n  - 在调用本 Skill 的同时**另起进程**用相同凭证调任意 Zoom REST API（如 `curl` 直接打 `api.zoom.us`）；\n  - 注入参数、拼接 URL、构造任意 JSON payload 绕过 CLI 校验逻辑。\n  脚本遵循\"最小暴露面\"原则：CLI 只暴露 7 个白名单 action，**任何其他调用路径都视为越权**。\n- **强人类确认**：`create_meeting` 与 `delete_meeting` 在执行前必须获得用户显式确认；`delete_meeting` 命令还需附加 `--yes` 参数。\n\n## 凭证配置\n\n在 `.env` 文件中配置（**仅 chmod 600，不要提交到任何 Git 仓库**）：\n\n```env\nZOOM_ACCOUNT_ID=你的AccountID\nZOOM_CLIENT_ID=你的ClientID\nZOOM_CLIENT_SECRET=你的ClientSecret\nZOOM_USER_ID=你的用户邮箱或user_id\n```\n\n> ⚠️ 完整的安全规范见下一节 `## 凭证安全`。\n\n**Token 获取方式**：Server-to-Server OAuth，机器对机器，无需用户交互授权。\n\n## 凭证安全\n\n`.env` 中的 `ZOOM_CLIENT_SECRET` 是长期有效的账户级凭据，等同于账户管理员口令。**必须**遵守：\n\n- **加入 `.gitignore`**：本仓库 `.gitignore` 已包含 `.env`；同步确保 IDE、备份工具、文件同步（iCloud / Dropbox / OneDrive / 坚果云）不会自动上传该文件。\n- **限制文件权限**：`chmod 600 .env`；`scripts/zoom-s2s.py` 缓存的 `~/.zoom-s2s-token.json` 同样敏感（已自动 `chmod 600`），**不要**复制到剪贴板、聊天窗口、终端截图、报错工单、AI 对话上下文或第三方日志服务。\n- **不要在共享环境复用**：CI runner、公用跳板机、容器镜像、共享开发机中复用同一份凭据 ≈ 凭据公开。`Account ID + Client ID + Client Secret` 三元组可换得 1 小时有效的访问令牌。\n- **最小权限**：按 `## 最小权限配置建议` 表按需开启 Scope；不需要的 Action 不要勾选对应权限；`delete_meeting` 之外的写权限（`meeting:write:update`、`user:write:*`、`account:write:*`）默认不要开。\n- **独立 App**：为此 Skill 单独创建一个 Zoom Server-to-Server App，**不要**复用其他业务 App 的凭据；一旦泄露，旋转该 App 的凭据即可，不影响其他业务。\n- **凭据泄露应急**：在 Zoom Marketplace 删除该 App → 重新创建并轮换 `ACCOUNT_ID` / `CLIENT_ID` / `CLIENT_SECRET` / `USER_ID` 四项 → `rm -f ~/.zoom-s2s-token.json` 强制下次重新认证 → 复盘泄露路径。\n\n## 核心脚本\n\n`scripts/zoom-s2s.py` — 纯 Python，无外部依赖，兼容 Python 3.7+。\n\n```bash\ncd ~/.agents/skills/zoom-meeting-admin/scripts\n\n# 获取帮助\npython3 zoom-s2s.py help\n\n# 列出即将到来的会议\npython3 zoom-s2s.py list_meetings <user> <page_size> upcoming\n\n# 获取单个会议详情\npython3 zoom-s2s.py get_meeting <meeting_id>\n\n# 创建会议 (start_time: YYYY-MM-DDTHH:MM:SS)\npython3 zoom-s2s.py create_meeting \"<主题>\" \"<start_time>\" <时长分钟> [时区] [密码]\n# 创建周期性会议（每周一，7次，每次120分钟；weekly_days=\"2\" = Zoom 编码周一）\npython3 zoom-s2s.py create_meeting \"CSM公开课\" \"2026-05-23T08:00:00\" 120 Asia/Shanghai \"\" 2 1 2 7\npython3 zoom-s2s.py create_meeting \"煎饼果子讨论会\" \"2026-05-05T10:00:00\" 60 Asia/Shanghai\n\n# 删除会议\npython3 zoom-s2s.py delete_meeting <meeting_id>\n\n# 获取云录像\npython3 zoom-s2s.py recordings <user> <page_size>\n\n# 获取用户信息\npython3 zoom-s2s.py get_user [user]\n\n# 列出账户下所有用户\npython3 zoom-s2s.py list_users [page_size]\n```\n\n## Token 缓存\n\n脚本自动缓存 Token 到 `~/.zoom-s2s-token.json`（有效期约 50 分钟），重复调用无需每次重新认证。\n\n## 常用操作快速参考\n\n| 操作 | 命令 |\n|------|------|\n| 列出最近5个会议 | `list_meetings <user> 5 upcoming` |\n| 列出最近10个历史会议 | `list_meetings <user> 10 past` |\n| 创建明天10点会议 | `create_meeting \"主题\" \"YYYY-MM-DDT10:00:00\" 60 Asia/Shanghai` |\n| 创建周期性会议（每周一） | `create_meeting \"主题\" \"YYYY-MM-DDT20:00:00\" 120 America/New_York \"\" 2 1 2 7` |\n| 创建月度会议（每月15号） | `create_meeting \"主题\" \"YYYY-MM-15T10:00:00\" 60 Asia/Shanghai \"\" 3 1 15 12` |\n| 创建月度会议（第N个周二） | `create_meeting \"主题\" \"...\" 60 ... \"\" 3 1 3 6 \"\" \"\" 2` |\n| 获取会议详情 | `get_meeting <id>` |\n| 删除会议 | `delete_meeting <id> --yes` |\n| 获取云录像 | `recordings <user> 10` |\n\n## 最小权限配置建议\n\n根据实际使用场景按需开通 scope，不需要的功能不要授权：\n\n| 功能 | 所需 Scope | 建议 |\n|------|-----------|------|\n| 列出会议 | `meeting:read:list_meetings` | ✅ 核心 |\n| 查看会议详情 | `meeting:read:meeting` | ✅ 核心 |\n| 创建会议 | `meeting:write:create` | 按需开启 |\n| **删除会议** | `meeting:write:delete` | ⚠️ 谨慎开启 |\n| **读取云录像** | `cloud_recording:read:list_user_recordings` | ⚠️ 谨慎开启 |\n| **列出账户用户** | `user:read:list_users` | ⚠️ 谨慎开启 |\n\n> 建议为此 Skill 单独创建一个 Zoom Server-to-Server App，不要复用已有 App 的凭证。\n\n## Agent 调用规范\n\n- **创建会议前**：向用户确认主题、时间、时长，再执行。\n- **删除会议前**：必须向用户明确展示会议信息并获得确认，命令需附加 `--yes` 参数。\n- **禁止超范围调用**：仅允许文档中列出的 Action，不得构造任意 Zoom REST API 请求。\n\n## 创建周期性会议\n\n`create_meeting` 通过位置参数直接支持周期性会议（**无需绕过 CLI**）：\n\n```bash\npython3 zoom-s2s.py create_meeting \"<主题>\" \"<start_time>\" <duration> [timezone] [password] \\\n  [recurrence_type] [repeat_interval] [weekly_days] [end_times] [end_date_time] \\\n  [monthly_day] [monthly_weeks]\n```\n\n| 参数 | 适用 type | 说明 | 示例 |\n|------|----------|------|------|\n| `recurrence_type` | 全部 | 1=每日, 2=每周, 3=每月 | `2` |\n| `repeat_interval` | 全部 | 每几周/天/月重复 | `1` |\n| `weekly_days` | type=2, type=3+monthly_weeks | 周几字符串（Zoom 编码：**1=周日, 2=周一, 3=周二, ..., 7=周六**）| `\"2\"` = 周一, `\"3,5\"` = 周二+周四 |\n| `end_times` | 全部 | 总共几次 | `7` |\n| `end_date_time` | 全部 | 结束日期（二选一）| `\"2026-10-06T00:00:00Z\"` |\n| `monthly_day` | type=3 | 每月第几天字符串（1-31，单值或逗号分隔）| `\"15\"` 或 `\"1,15\"` |\n| `monthly_weeks` | type=3 | 每月第几个周次（-1=最后, 1-4），配合 `weekly_days` | `2` |\n\n> ⚠️ **重要：`weekly_days` 是 Zoom 编码，不是 ISO 编码。** 1=周日（不是周一）。常见误用：\n> - 想约周一 → `weekly_days=\"2\"`（不是 `\"1\"`）\n> - 想约周六 → `weekly_days=\"7\"`（不是 `\"6\"`）\n> - 想约周日 → `weekly_days=\"1\"`\n\n### 示例：每周一 20:00（EDT），共 7 次，每次 2 小时\n```bash\npython3 zoom-s2s.py create_meeting \"每周一的产品同步\" \\\n  \"2026-08-24T20:00:00\" 120 America/New_York \"\" 2 1 2 7\n# weekly_days=\"2\" = Zoom 编码 2 = 周一\n```\n\n### 示例：每月 15 号 10:00，共 12 次\n```bash\npython3 zoom-s2s.py create_meeting \"月度复盘\" \\\n  \"2026-08-15T10:00:00\" 60 Asia/Shanghai \"\" 3 1 15 12\n# positional: topic, start_time, duration, tz, password, type=3, repeat=1, weekly_days=15, end_times=12\n# 解释: monthly_day=\"15\"（每月 15 号）\n```\n\n### 示例：每月第 2 个周二 20:00，共 6 次\n```bash\npython3 zoom-s2s.py create_meeting \"月度董事会\" \\\n  \"2026-08-25T20:00:00\" 60 America/New_York \"\" 3 1 3 6 \"\" \"\" 2\n# positional: ..., type=3, repeat=1, weekly_days=\"3\", end_times=6, end_date_time=\"\", monthly_day=\"\", monthly_weeks=2\n# 解释: monthly_weeks=2 + weekly_days=\"3\" = 每月第 2 个周二（Zoom 编码 3 = 周二）\n```\n\n**⚠️ 关键避坑：`weekly_days` / `monthly_day` 必须是字符串，不是数组！**\n\n| 错误写法 | 正确写法 |\n|---------|---------|\n| `\"weekly_days\": [6]` | `\"weekly_days\": \"6\"`（单日） |\n| `\"weekly_days\": [\"6\"]` | `\"weekly_days\": \"6\"` |\n|  | `\"weekly_days\": \"6,7\"`（多日，**周五+周六**——Zoom 编码） |\n|  | `\"weekly_days\": \"2,3,5\"`（**周一+周二+周四**——Zoom 编码） |\n|  | `\"weekly_days\": \"1,7\"`（**周日+周六**——Zoom 编码两端） |\n| `\"monthly_day\": [15]` | `\"monthly_day\": \"15\"` |\n|  | `\"monthly_day\": \"1,15\"`（每月 1 号和 15 号） |\n\n`weekly_days` Zoom 编码：1=周日，2=周一，3=周二，4=周三，5=周四，6=周五，7=周六。\n\n> ❗ **禁止**：当 CLI 参数不够用时，不得构造任意 payload 直接调用 `api_call` 或另起 `curl` 调用 Zoom API。如确需新参数，应扩展 `scripts/zoom-s2s.py` 中的 CLI action 并在 PR 中说明。\n\n## 踩坑记录\n\n1. **scope 错误 (4711)**：某些 API（如 `get_user`）需要在 App 里开通对应 scope，又如 `list_meetings` 需要在 App 里开通 `meeting:read:list_meetings` 权限\n2. **Token 有效期**：Server-to-Server Token 有效期 1 小时，脚本自动刷新并缓存\n3. **用户 ID**：可用邮箱，也可用 `list_users` 查 user_id\n4. **`weekly_days` / `monthly_day` 必须为字符串**：Zoom API 要求 `weekly_days`、`monthly_day` 是 `\"6\"` / `\"15\"` 这样的字符串，而非 `[6]` / `[15]` 数组，传数组会报 300 错误（CLI 已自动 `str()`，但调用方传入时仍需注意）。`weekly_days` 是 Zoom 编码（1=周日, 2=周一, ..., 7=周六），不是 ISO 编码。\n5. **月度循环的两种写法**：`monthly_day` 表示\"每月第几天\"，`monthly_weeks + weekly_days` 表示\"每月第几个周几\"。两者二选一，不要同时给；同时给会让 Zoom 拒绝（300 错误）\n\nFile v1.0.5:README.md\n\n# SKILL of Zoom Server-to-Server OAuth REST API\n\nManage and schedule Zoom meetings REST API directly via Server-to-Server OAuth — no VPS required, no MCP protocol needed.\n\n> EN | [中文](README.zh-cn.md)\n\n## Setup Steps\n\n1. Log in to https://marketplace.zoom.us/\n2. From the \"Develop\" dropdown, select \"build app\" and create an app of type `Server-to-Server OAuth`\n3. Add required OAuth Scopes\n4. Get the credentials\n5. Activate the app\n6. Invoke this SKILL in your AI agent\n\n## Credentials\n\n> ⚠️ **The `ZOOM_CLIENT_SECRET` in `.env` is equivalent to an account-admin password.** Anyone holding the `ACCOUNT_ID + CLIENT_ID + CLIENT_SECRET` triple can mint a 1-hour account-level access token that reads all meeting metadata, cloud recordings, and can delete meetings.\n>\n> - Never commit `.env` to git. Confirm your IDE, backup tools, and file-sync services (iCloud / Dropbox / OneDrive / Nutstore) are not auto-uploading it.\n> - `chmod 600 .env`. The token cache at `~/.zoom-s2s-token.json` is auto-set to `chmod 600` by the script.\n> - Use the **minimum scopes** you actually need (see table below). Do not enable `meeting:write:delete`, `cloud_recording:read:*`, or `user:read:list_users` unless required.\n> - Create a **dedicated** Server-to-Server App for this skill — do not reuse credentials from other business apps.\n> - If leaked: delete the App in Zoom Marketplace → re-create and rotate all four values → `rm -f ~/.zoom-s2s-token.json`.\n\nEdit the `.env` file with your Zoom Server-to-Server OAuth App credentials:\n\n```env\nZOOM_ACCOUNT_ID=yourAccountID\nZOOM_CLIENT_ID=yourClientID\nZOOM_CLIENT_SECRET=yourClientSecret\nZOOM_USER_ID=your_user_email_or_user_id\n```\n\n\n## Required OAuth Scopes\n\nEnable these in your Zoom Marketplace Server-to-Server OAuth App:\n\n| Scope | Purpose |\n|-------|---------|\n| `meeting:read:list_meetings` | List meetings |\n| `meeting:write:create` | Create meetings |\n| `meeting:write:delete` | Delete meetings |\n| `cloud_recording:read:list_user_recordings` | View cloud recordings |\n| `user:read:list_users` | List users |\n| `user:read:user` | Get user info |\n\n## Quick Start\n\n```bash\ncd ~/.agents/skills/zoom-s2s-oauth/scripts\n\n# List upcoming meetings\npython3 zoom-s2s.py list_meetings service@uperform.cn 5 upcoming\n\n# Create a meeting (start_time format: YYYY-MM-DDTHH:MM:SS)\npython3 zoom-s2s.py create_meeting \"Pancake Discussion\" \"2026-05-05T10:00:00\" 60 Asia/Shanghai\n\n# Get cloud recordings\npython3 zoom-s2s.py recordings service@uperform.cn 10\n```\n\n## Directory Structure\n\n```\nzoom-s2s-oauth/\n├── SKILL.md           # AI Agent invocation guide\n├── README.md          # This file\n├── README.zh-cn.md    # 中文版\n├── .env               # Credentials (do NOT commit to git!)\n└── scripts/\n    └── zoom-s2s.py    # Main script (pure Python3, no external dependencies)\n```\n\n\n## Comparison: MCP vs Server-to-Server REST\n\n| | MCP | Server-to-Server REST |\n|---|---|---|\n| Requires VPS | ✅ Yes (OAuth callback) | ❌ No |\n| Protocol | MCP (JSON-RPC) | Standard REST (pure Python, no deps) |\n| Token | User-Managed OAuth | Server-to-Server OAuth |\n| Complexity | High (proxy+OAuth) | Low (direct call) |\n| Features | Zoom MCP tools | 7 whitelisted CLI actions (list/get/create/delete meeting, get/list user, list recordings) |\n\nIf you only need core Zoom meeting/recording features, Server-to-Server REST is simpler.\n\nFile v1.0.5:_meta.json\n\n{\n  \"ownerId\": \"kn75w6500mvryv9p0k3czdfww982r5xh\",\n  \"slug\": \"zoom-meeting-admin\",\n  \"version\": \"1.0.5\",\n  \"publishedAt\": 1787045281893\n}\n\nFile v1.0.5:README.zh-cn.md\n\n# SKILL of Zoom Server-to-Server OAuth REST API \n\n用 Server-to-Server OAuth 直接调 Zoom meeting REST API，不需要 VPS，不需要 MCP 协议，管理和安排ZOOM会议。\n\n> [EN](README.md) | 中文\n\n## 配置步骤\n\n1. 需要先手动登录 https://marketplace.zoom.us/\n2. 在 \"Develop\" 下拉菜单选 \"build app\", 创建一个 `Server-to-Server OAuth`类型的APP\n3. 添加必要的OAuth Scope。\n4. 获取相关凭证密码\n5. 激活APP\n6. 在AI agent中调用此 SKILL\n\n## 凭证配置\n\n> ⚠️ **`.env` 中的 `ZOOM_CLIENT_SECRET` 等同于账户管理员口令。** 持有 `ACCOUNT_ID + CLIENT_ID + CLIENT_SECRET` 三元组即可换取 1 小时有效的账户级访问令牌，**能读取该账户下所有会议元数据、云录像，并执行删除等破坏性操作**。\n>\n> - 千万不要把 `.env` 提交到 git。确认你的 IDE、备份工具、文件同步服务（iCloud / Dropbox / OneDrive / 坚果云）没有自动上传该文件。\n> - `chmod 600 .env`。脚本缓存的 token 文件 `~/.zoom-s2s-token.json` 由脚本自动 `chmod 600`。\n> - **按需开通最小 scope**（见下表）。未用到的功能不要勾选对应权限；不要轻易开启 `meeting:write:delete`、`cloud_recording:read:*`、`user:read:list_users`。\n> - 为本 Skill **单独创建一个** Server-to-Server App，不要复用其他业务 App 的凭据。\n> - 一旦泄露：在 Zoom Marketplace 删除该 App → 重新创建并轮换四项值 → `rm -f ~/.zoom-s2s-token.json` 强制重新认证。\n\n编辑 `.env` 文件，填入你的 Zoom Server-to-Server OAuth App 凭证：\n\n```env\nZOOM_ACCOUNT_ID=你的AccountID\nZOOM_CLIENT_ID=你的ClientID\nZOOM_CLIENT_SECRET=你的ClientSecret\nZOOM_USER_ID=你的用户邮箱或user_id\n```\n\n\n## 需要的 OAuth Scope\n\n在 Zoom Marketplace 你的 Server-to-Server OAuth App 里开通：\n\n| Scope | 用途 |\n|-------|------|\n| `meeting:read:list_meetings` | 列出会议 |\n| `meeting:write:create` | 创建会议 |\n| `meeting:write:delete` | 删除会议 |\n| `cloud_recording:read:list_user_recordings` | 查看云录像 |\n| `user:read:list_users` | 列出用户 |\n| `user:read:user` | 获取用户信息 |\n\n## 快速开始\n\n```bash\ncd ~/.agents/skills/zoom-s2s-oauth/scripts\n\n# 列出最近5个会议\npython3 zoom-s2s.py list_meetings service@uperform.cn 5 upcoming\n\n# 创建会议 (start_time 格式: YYYY-MM-DDTHH:MM:SS)\npython3 zoom-s2s.py create_meeting \"煎饼果子讨论会\" \"2026-05-05T10:00:00\" 60 Asia/Shanghai\n\n# 获取云录像\npython3 zoom-s2s.py recordings service@uperform.cn 10\n```\n\n## 目录结构\n\n```\nzoom-s2s-oauth/\n├── SKILL.md           # AI Agent 调用说明\n├── README.md          # 本文件\n├── .env               # 凭证配置 (不要提交到 git!)\n└── scripts/\n    └── zoom-s2s.py    # 主脚本 (纯 Python3，无外部依赖)\n```\n\n\n## 对比：MCP vs Server-to-Server REST\n\n| | MCP 方式 | Server-to-Server REST |\n|---|---|---|\n| 需要 VPS | ✅ 需要 (OAuth 回调) | ❌ 不需要 |\n| 协议 | MCP (JSON-RPC) | 标准 REST (Python 无外部依赖) |\n| Token | User-Managed OAuth | Server-to-Server OAuth |\n| 复杂度 | 高 (代理+OAuth) | 低 (直接调) |\n| 功能 | Zoom MCP 工具集 | 7 个白名单 CLI action（list/get/create/delete meeting、get/list user、list recordings） |\n\n如果你只需要调用 Zoom 会议/录像等核心功能，Server-to-Server REST 方式更简单。\n\nFile v1.0.5:skill-card.md\n\n## Description:\n\nManage Zoom meetings, cloud recordings, and account users through a fixed Zoom Server-to-Server OAuth REST CLI.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[mebusw](https://clawhub.ai/user/mebusw)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and operators use this skill to list, inspect, create, and delete Zoom meetings, query cloud recordings, and look up account users from an agent using a dedicated Zoom Server-to-Server OAuth app.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Account-level Zoom credentials can expose sensitive meeting data, cloud recordings, and administrative actions.\n\nMitigation: Install only in a private environment, use a dedicated Zoom Server-to-Server app, and enable only the minimum scopes needed.\n\nRisk: Delete, recording, and user-list scopes increase the impact of credential misuse.\n\nMitigation: Avoid enabling delete, recording, or user-list scopes unless required, and require explicit user confirmation before destructive meeting actions.\n\nRisk: Persistently cached bearer tokens may remain usable after account changes or suspected exposure.\n\nMitigation: Keep credential and token files at 0600 permissions, avoid shared or synced folders, and clear or rotate ~/.zoom-s2s-token.json after suspected exposure.\n\n## Reference(s):\n\n- [Server-resolved source repository](https://github.com/mebusw/zoom-meeting-admin)\n- [ClawHub skill page](https://clawhub.ai/mebusw/skills/zoom-meeting-admin)\n- [Artifact README](artifact/README.md)\n- [Zoom Marketplace](https://marketplace.zoom.us/)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Shell commands, Configuration, Guidance]\n\n**Output Format:** [Markdown guidance with CLI commands and Zoom API response text]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Requires Python 3.7+, network access to zoom.us and api.zoom.us, and local Zoom Server-to-Server OAuth credentials.]\n\n## Skill Version(s):\n\n1.0.5 (source: server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.0.4: 9 files, 13005 bytes\n\nFiles: .env.sample (744b), .gitignore (14b), README.md (2363b), README.zh-cn.md (2326b), scripts (0b), scripts/zoom-s2s.py (11128b), skill-card.md (2430b), SKILL.md (9766b), _meta.json (137b)\n\nFile v1.0.4:SKILL.md\n\n---\nname: zoom-meeting-admin\nallowed-tools: Bash(python3:*) Bash(ls:*) Bash(cat:*) Read\ncompatibility: Requires Python 3.7+, network access to zoom.us and api.zoom.us, and a local .env with Zoom Server-to-Server OAuth credentials.\ndescription: Manage Zoom meetings, cloud recordings, and account users via a Server-to-Server OAuth REST script. Use this skill when the user wants to list, view, create, or delete a scheduled Zoom meeting; query cloud recordings for a user; or look up account users. Actions are restricted to a fixed list (list/get/create/delete meeting, get/list user, list recordings) — the script does not perform arbitrary Zoom API calls. create_meeting and delete_meeting require explicit user confirmation before execution. Requires a Zoom Server-to-Server OAuth app and a local .env with ACCOUNT_ID, CLIENT_ID, CLIENT_SECRET, USER_ID.\n---\n\n# Zoom Server-to-Server OAuth REST API\n\n## 权限与约束\n\n本 Skill 通过 `scripts/zoom-s2s.py` 调用 Zoom Server-to-Server OAuth REST API，不实现\"通用 REST 代理\"。\n\n- **声明的工具**：`Bash(python3:*)`（执行 `scripts/zoom-s2s.py`）、`Bash(ls:*)` / `Bash(cat:*)`（查看脚本输出与缓存）、`Read`（读取凭证文件与文档）。\n- **网络访问**：向 `https://zoom.us/oauth/token` 与 `https://api.zoom.us/v2/*` 发起 HTTPS 请求，传输头包含 `Authorization: Bearer <token>`。\n- **文件写入**：在 `~/.zoom-s2s-token.json` 缓存访问令牌（已自动 `chmod 600`）。\n- **凭证读取**：从仓库根目录的 `.env` 读取 `ZOOM_ACCOUNT_ID` / `ZOOM_CLIENT_ID` / `ZOOM_CLIENT_SECRET` / `ZOOM_USER_ID`。\n- **允许的 Action（白名单）**——禁止构造任意 Zoom REST 请求或调用未列出的端点：\n  - 会议：`list_meetings` / `get_meeting` / `create_meeting` / `delete_meeting`\n  - 用户：`get_user` / `list_users`\n  - 录像：`recordings`\n- **越权防护**：脚本未导出 `api_call` 给上层调用；不得通过修改脚本、注入参数、拼接 URL 等方式旁路调用白名单外的 Zoom 端点（如 `DELETE /users/{id}`、`PATCH /accounts/{id}` 等高风险端点）。\n- **强人类确认**：`create_meeting` 与 `delete_meeting` 在执行前必须获得用户显式确认；`delete_meeting` 命令还需附加 `--yes` 参数。\n\n## 凭证配置\n\n在 `.env` 文件中配置（**仅 chmod 600，不要提交到任何 Git 仓库**）：\n\n```env\nZOOM_ACCOUNT_ID=你的AccountID\nZOOM_CLIENT_ID=你的ClientID\nZOOM_CLIENT_SECRET=你的ClientSecret\nZOOM_USER_ID=你的用户邮箱或user_id\n```\n\n> ⚠️ 完整的安全规范见下一节 `## 凭证安全`。\n\n**Token 获取方式**：Server-to-Server OAuth，机器对机器，无需用户交互授权。\n\n## 凭证安全\n\n`.env` 中的 `ZOOM_CLIENT_SECRET` 是长期有效的账户级凭据，等同于账户管理员口令。**必须**遵守：\n\n- **加入 `.gitignore`**：本仓库 `.gitignore` 已包含 `.env`；同步确保 IDE、备份工具、文件同步（iCloud / Dropbox / OneDrive / 坚果云）不会自动上传该文件。\n- **限制文件权限**：`chmod 600 .env`；`scripts/zoom-s2s.py` 缓存的 `~/.zoom-s2s-token.json` 同样敏感（已自动 `chmod 600`），**不要**复制到剪贴板、聊天窗口、终端截图、报错工单、AI 对话上下文或第三方日志服务。\n- **不要在共享环境复用**：CI runner、公用跳板机、容器镜像、共享开发机中复用同一份凭据 ≈ 凭据公开。`Account ID + Client ID + Client Secret` 三元组可换得 1 小时有效的访问令牌。\n- **最小权限**：按 `## 最小权限配置建议` 表按需开启 Scope；不需要的 Action 不要勾选对应权限；`delete_meeting` 之外的写权限（`meeting:write:update`、`user:write:*`、`account:write:*`）默认不要开。\n- **独立 App**：为此 Skill 单独创建一个 Zoom Server-to-Server App，**不要**复用其他业务 App 的凭据；一旦泄露，旋转该 App 的凭据即可，不影响其他业务。\n- **凭据泄露应急**：在 Zoom Marketplace 删除该 App → 重新创建并轮换 `ACCOUNT_ID` / `CLIENT_ID` / `CLIENT_SECRET` / `USER_ID` 四项 → `rm -f ~/.zoom-s2s-token.json` 强制下次重新认证 → 复盘泄露路径。\n\n## 核心脚本\n\n`scripts/zoom-s2s.py` — 纯 Python，无外部依赖，兼容 Python 3.7+。\n\n```bash\ncd ~/.agents/skills/zoom-meeting-admin/scripts\n\n# 获取帮助\npython3 zoom-s2s.py help\n\n# 列出即将到来的会议\npython3 zoom-s2s.py list_meetings <user> <page_size> upcoming\n\n# 获取单个会议详情\npython3 zoom-s2s.py get_meeting <meeting_id>\n\n# 创建会议 (start_time: YYYY-MM-DDTHH:MM:SS)\npython3 zoom-s2s.py create_meeting \"<主题>\" \"<start_time>\" <时长分钟> [时区] [密码]\n# 创建周期性会议（每周二，7次，每次120分钟）\npython3 zoom-s2s.py create_meeting \"CSM公开课\" \"2026-05-23T08:00:00\" 120 Asia/Shanghai \"\" 2 1 2 7\npython3 zoom-s2s.py create_meeting \"煎饼果子讨论会\" \"2026-05-05T10:00:00\" 60 Asia/Shanghai\n\n# 删除会议\npython3 zoom-s2s.py delete_meeting <meeting_id>\n\n# 获取云录像\npython3 zoom-s2s.py recordings <user> <page_size>\n\n# 获取用户信息\npython3 zoom-s2s.py get_user [user]\n\n# 列出账户下所有用户\npython3 zoom-s2s.py list_users [page_size]\n```\n\n## Token 缓存\n\n脚本自动缓存 Token 到 `~/.zoom-s2s-token.json`（有效期约 50 分钟），重复调用无需每次重新认证。\n\n## 常用操作快速参考\n\n| 操作 | 命令 |\n|------|------|\n| 列出最近5个会议 | `list_meetings <user> 5 upcoming` |\n| 列出最近10个历史会议 | `list_meetings <user> 10 past` |\n| 创建明天10点会议 | `create_meeting \"主题\" \"YYYY-MM-DDT10:00:00\" 60 Asia/Shanghai` |\n| 创建周期性会议 | `create_meeting \"主题\" \"YYYY-MM-DDT20:00:00\" 120 America/New_York \"\" 2 1 2 7` |\n| 获取会议详情 | `get_meeting <id>` |\n| 删除会议 | `delete_meeting <id> --yes` |\n| 获取云录像 | `recordings <user> 10` |\n\n## 最小权限配置建议\n\n根据实际使用场景按需开通 scope，不需要的功能不要授权：\n\n| 功能 | 所需 Scope | 建议 |\n|------|-----------|------|\n| 列出会议 | `meeting:read:list_meetings` | ✅ 核心 |\n| 查看会议详情 | `meeting:read:meeting` | ✅ 核心 |\n| 创建会议 | `meeting:write:create` | 按需开启 |\n| **删除会议** | `meeting:write:delete` | ⚠️ 谨慎开启 |\n| **读取云录像** | `cloud_recording:read:list_user_recordings` | ⚠️ 谨慎开启 |\n| **列出账户用户** | `user:read:list_users` | ⚠️ 谨慎开启 |\n\n> 建议为此 Skill 单独创建一个 Zoom Server-to-Server App，不要复用已有 App 的凭证。\n\n## Agent 调用规范\n\n- **创建会议前**：向用户确认主题、时间、时长，再执行。\n- **删除会议前**：必须向用户明确展示会议信息并获得确认，命令需附加 `--yes` 参数。\n- **禁止超范围调用**：仅允许文档中列出的 Action，不得构造任意 Zoom REST API 请求。\n\n## 创建周期性会议\n\n### CLI 方式\n\n`create_meeting` 额外支持周期性参数（按位置传递）：\n\n```bash\npython3 zoom-s2s.py create_meeting \"<主题>\" \"<start_time>\" <duration> [timezone] [password] \\\n  [recurrence_type] [repeat_interval] [weekly_days] [end_times] [end_date_time]\n```\n\n| 参数 | 说明 | 示例 |\n|------|------|------|\n| `recurrence_type` | 1=每日, 2=每周, 3=每月 | `2` |\n| `repeat_interval` | 每几周/天重复 | `1` |\n| `weekly_days` | 周几（字符串，1=周一~7=周日）| `\"2\"` |\n| `end_times` | 总共几次 | `7` |\n| `end_date_time` | 结束日期（二选一）| `\"2026-10-06T00:00:00Z\"` |\n\n**示例：每周二 20:00，共 7 次，每次 2 小时**\n```bash\npython3 zoom-s2s.py create_meeting \"北美龙虾 AI 数字员工系列第 2 期\" \\\n  \"2026-08-18T20:00:00\" 120 America/New_York \"\" 2 1 2 7\n```\n\n### API Payload 方式\n\n创建 `type=8`（周期性会议）的 `recurrence` 参数说明：\n\n| recurrence.type | 说明 | 可用字段 | 是否可用 |\n|---|---|---|---|\n| 1 | 每日循环（Daily） | `end_date_time` 或 `count` | ✅ |\n| 2 | 每周循环（Weekly） | `weekly_days`（字符串）, `end_date_time` 或 `count` | ✅ |\n| 3 | 每月循环（Monthly） | `monthly_day` 或 `monthly_weeks` + `weekly_days` | ✅ |\n\n**⚠️ 关键避坑：`weekly_days` 必须是字符串，不是数组！**\n\n| 错误写法 | 正确写法 |\n|---------|---------|\n| `\"weekly_days\": [6]` | `\"weekly_days\": \"6\"` |\n| `\"weekly_days\": [\"6\"]` | `\"weekly_days\": \"6\"`（单日） |\n|  | `\"weekly_days\": \"6,0\"`（多日，周六+周日） |\n\n**weekly_days 取值**：1=周一 ~ 7=周日\n\n**示例**：通过 `api_call` 直接 POST 创建周期性会议：\n```python\npayload = {\n    \"topic\": \"CSM公开课\",\n    \"type\": 8,\n    \"start_time\": \"2026-05-23T08:00:00\",\n    \"duration\": 540,\n    \"timezone\": \"Asia/Shanghai\",\n    \"recurrence\": {\n        \"type\": 2,\n        \"repeat_interval\": 1,\n        \"weekly_days\": \"6,0\",   # 周六+周日，字符串！\n        \"end_date_time\": \"2026-05-24T00:00:00Z\"\n    },\n    \"settings\": {\n        \"host_video\": True,\n        \"participant_video\": True,\n        \"join_before_host\": False,\n        \"mute_upon_entry\": False\n    }\n}\n```\n\n**多日示例**（周一+周三+周五）：\n```python\n\"weekly_days\": \"1,3,5\"\n```\n\n## 踩坑记录\n\n1. **scope 错误 (4711)**：某些 API（如 `get_user`）需要在 App 里开通对应 scope，又如 `list_meetings` 需要在 App 里开通 `meeting:read:list_meetings` 权限\n2. **Token 有效期**：Server-to-Server Token 有效期 1 小时，脚本自动刷新并缓存\n3. **用户 ID**：可用邮箱，也可用 `list_users` 查 user_id\n4. **`weekly_days` 必须为字符串**：Zoom API 要求 `weekly_days` 是 `\"6\"` 这样的字符串，而非 `[6]` 数组，传数组会报 300 错误\n\nFile v1.0.4:README.md\n\n# SKILL of Zoom Server-to-Server OAuth REST API\n\nManage and schedule Zoom meetings REST API directly via Server-to-Server OAuth — no VPS required, no MCP protocol needed.\n\n> EN | [中文](README.zh-cn.md)\n\n## Setup Steps\n\n1. Log in to https://marketplace.zoom.us/\n2. From the \"Develop\" dropdown, select \"build app\" and create an app of type `Server-to-Server OAuth`\n3. Add required OAuth Scopes\n4. Get the credentials\n5. Activate the app\n6. Invoke this SKILL in your AI agent\n\n## Credentials\n\nEdit the `.env` file with your Zoom Server-to-Server OAuth App credentials:\n\n```env\nZOOM_ACCOUNT_ID=yourAccountID\nZOOM_CLIENT_ID=yourClientID\nZOOM_CLIENT_SECRET=yourClientSecret\nZOOM_USER_ID=your_user_email_or_user_id\n```\n\n\n## Required OAuth Scopes\n\nEnable these in your Zoom Marketplace Server-to-Server OAuth App:\n\n| Scope | Purpose |\n|-------|---------|\n| `meeting:read:list_meetings` | List meetings |\n| `meeting:write:create` | Create meetings |\n| `meeting:write:delete` | Delete meetings |\n| `cloud_recording:read:list_user_recordings` | View cloud recordings |\n| `user:read:list_users` | List users |\n| `user:read:user` | Get user info |\n\n## Quick Start\n\n```bash\ncd ~/.agents/skills/zoom-s2s-oauth/scripts\n\n# List upcoming meetings\npython3 zoom-s2s.py list_meetings service@uperform.cn 5 upcoming\n\n# Create a meeting (start_time format: YYYY-MM-DDTHH:MM:SS)\npython3 zoom-s2s.py create_meeting \"Pancake Discussion\" \"2026-05-05T10:00:00\" 60 Asia/Shanghai\n\n# Get cloud recordings\npython3 zoom-s2s.py recordings service@uperform.cn 10\n```\n\n## Directory Structure\n\n```\nzoom-s2s-oauth/\n├── SKILL.md           # AI Agent invocation guide\n├── README.md          # This file\n├── README.zh-cn.md    # 中文版\n├── .env               # Credentials (do NOT commit to git!)\n└── scripts/\n    └── zoom-s2s.py    # Main script (pure Python3, no external dependencies)\n```\n\n\n## Comparison: MCP vs Server-to-Server REST\n\n| | MCP | Server-to-Server REST |\n|---|---|---|\n| Requires VPS | ✅ Yes (OAuth callback) | ❌ No |\n| Protocol | MCP (JSON-RPC) | Standard REST (pure Python, no deps) |\n| Token | User-Managed OAuth | Server-to-Server OAuth |\n| Complexity | High (proxy+OAuth) | Low (direct call) |\n| Features | Zoom MCP tools | All Zoom REST API |\n\nIf you only need core Zoom meeting/recording features, Server-to-Server REST is simpler.\n\nFile v1.0.4:_meta.json\n\n{\n  \"ownerId\": \"kn75w6500mvryv9p0k3czdfww982r5xh\",\n  \"slug\": \"zoom-meeting-admin\",\n  \"version\": \"1.0.4\",\n  \"publishedAt\": 1786623750781\n}\n\nFile v1.0.4:README.zh-cn.md\n\n# SKILL of Zoom Server-to-Server OAuth REST API \n\n用 Server-to-Server OAuth 直接调 Zoom meeting REST API，不需要 VPS，不需要 MCP 协议，管理和安排ZOOM会议。\n\n> [EN](README.md) | 中文\n\n## 配置步骤\n\n1. 需要先手动登录 https://marketplace.zoom.us/\n2. 在 \"Develop\" 下拉菜单选 \"build app\", 创建一个 `Server-to-Server OAuth`类型的APP\n3. 添加必要的OAuth Scope。\n4. 获取相关凭证密码\n5. 激活APP\n6. 在AI agent中调用此 SKILL\n\n## 凭证配置\n\n编辑 `.env` 文件，填入你的 Zoom Server-to-Server OAuth App 凭证：\n\n```env\nZOOM_ACCOUNT_ID=你的AccountID\nZOOM_CLIENT_ID=你的ClientID\nZOOM_CLIENT_SECRET=你的ClientSecret\nZOOM_USER_ID=你的用户邮箱或user_id\n```\n\n\n## 需要的 OAuth Scope\n\n在 Zoom Marketplace 你的 Server-to-Server OAuth App 里开通：\n\n| Scope | 用途 |\n|-------|------|\n| `meeting:read:list_meetings` | 列出会议 |\n| `meeting:write:create` | 创建会议 |\n| `meeting:write:delete` | 删除会议 |\n| `cloud_recording:read:list_user_recordings` | 查看云录像 |\n| `user:read:list_users` | 列出用户 |\n| `user:read:user` | 获取用户信息 |\n\n## 快速开始\n\n```bash\ncd ~/.agents/skills/zoom-s2s-oauth/scripts\n\n# 列出最近5个会议\npython3 zoom-s2s.py list_meetings service@uperform.cn 5 upcoming\n\n# 创建会议 (start_time 格式: YYYY-MM-DDTHH:MM:SS)\npython3 zoom-s2s.py create_meeting \"煎饼果子讨论会\" \"2026-05-05T10:00:00\" 60 Asia/Shanghai\n\n# 获取云录像\npython3 zoom-s2s.py recordings service@uperform.cn 10\n```\n\n## 目录结构\n\n```\nzoom-s2s-oauth/\n├── SKILL.md           # AI Agent 调用说明\n├── README.md          # 本文件\n├── .env               # 凭证配置 (不要提交到 git!)\n└── scripts/\n    └── zoom-s2s.py    # 主脚本 (纯 Python3，无外部依赖)\n```\n\n\n## 对比：MCP vs Server-to-Server REST\n\n| | MCP 方式 | Server-to-Server REST |\n|---|---|---|\n| 需要 VPS | ✅ 需要 (OAuth 回调) | ❌ 不需要 |\n| 协议 | MCP (JSON-RPC) | 标准 REST (Python 无外部依赖) |\n| Token | User-Managed OAuth | Server-to-Server OAuth |\n| 复杂度 | 高 (代理+OAuth) | 低 (直接调) |\n| 功能 | Zoom MCP 工具集 | 所有 Zoom REST API |\n\n如果你只需要调用 Zoom 会议/录像等核心功能，Server-to-Server REST 方式更简单。\n\nFile v1.0.4:skill-card.md\n\n## Description:\n\nManage Zoom meetings, cloud recordings, and account users via a Server-to-Server OAuth REST script.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[mebusw](https://clawhub.ai/user/mebusw)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nExternal users and developers use this skill to manage scheduled Zoom meetings, inspect meeting details, create recurring meetings, delete meetings after confirmation, query cloud recordings, and look up account users through a constrained Server-to-Server OAuth workflow.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill uses account-level Zoom Server-to-Server OAuth credentials and caches an access token locally.\n\nMitigation: Use a dedicated least-privilege Zoom app, keep .env and token cache files chmod 600, and keep credentials out of prompts, logs, repositories, and shared environments.\n\nRisk: Meeting creation and deletion can change live Zoom account state.\n\nMitigation: Require a separate human confirmation before creating or deleting meetings, and enable delete and recording scopes only when they are needed.\n\nRisk: Evidence reports mismatches around API scope and meeting-creation confirmation.\n\nMitigation: Review or fix the api_call documentation and create_meeting confirmation mismatch before relying on this skill in a shared agent environment.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/mebusw/skills/zoom-meeting-admin)\n- [Server-resolved GitHub provenance](https://github.com/mebusw/zoom-meeting-admin)\n- [Zoom Marketplace](https://marketplace.zoom.us/)\n- [README.md](artifact/README.md)\n- [README.zh-cn.md](artifact/README.zh-cn.md)\n\n## Skill Output:\n\n**Output Type(s):** [text, JSON, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown guidance with shell command examples and JSON API responses from the Zoom helper script]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Requires Python 3.7+, network access to zoom.us and api.zoom.us, and local Zoom Server-to-Server OAuth credentials.]\n\n## Skill Version(s):\n\n1.0.4 (source: server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.0.3: 6 files, 11375 bytes\n\nFiles: README.md (2363b), README.zh-cn.md (2326b), scripts/zoom-s2s.py (9766b), skill-card.md (2183b), SKILL.md (8643b), _meta.json (137b)\n\nFile v1.0.3:SKILL.md\n\n---\nname: zoom-meeting-admin\nallowed-tools: Bash(python3:*) Bash(ls:*) Bash(cat:*) Read\ncompatibility: Requires Python 3.7+, network access to zoom.us and api.zoom.us, and a local .env with Zoom Server-to-Server OAuth credentials.\ndescription: Manage Zoom meetings, cloud recordings, and account users via a Server-to-Server OAuth REST script. Use this skill when the user wants to list, view, create, or delete a scheduled Zoom meeting; query cloud recordings for a user; or look up account users. Actions are restricted to a fixed list (list/get/create/delete meeting, get/list user, list recordings) — the script does not perform arbitrary Zoom API calls. create_meeting and delete_meeting require explicit user confirmation before execution. Requires a Zoom Server-to-Server OAuth app and a local .env with ACCOUNT_ID, CLIENT_ID, CLIENT_SECRET, USER_ID.\n---\n\n# Zoom Server-to-Server OAuth REST API\n\n## 权限与约束\n\n本 Skill 通过 `scripts/zoom-s2s.py` 调用 Zoom Server-to-Server OAuth REST API，不实现\"通用 REST 代理\"。\n\n- **声明的工具**：`Bash(python3:*)`（执行 `scripts/zoom-s2s.py`）、`Bash(ls:*)` / `Bash(cat:*)`（查看脚本输出与缓存）、`Read`（读取凭证文件与文档）。\n- **网络访问**：向 `https://zoom.us/oauth/token` 与 `https://api.zoom.us/v2/*` 发起 HTTPS 请求，传输头包含 `Authorization: Bearer <token>`。\n- **文件写入**：在 `~/.zoom-s2s-token.json` 缓存访问令牌（已自动 `chmod 600`）。\n- **凭证读取**：从仓库根目录的 `.env` 读取 `ZOOM_ACCOUNT_ID` / `ZOOM_CLIENT_ID` / `ZOOM_CLIENT_SECRET` / `ZOOM_USER_ID`。\n- **允许的 Action（白名单）**——禁止构造任意 Zoom REST 请求或调用未列出的端点：\n  - 会议：`list_meetings` / `get_meeting` / `create_meeting` / `delete_meeting`\n  - 用户：`get_user` / `list_users`\n  - 录像：`recordings`\n- **越权防护**：脚本未导出 `api_call` 给上层调用；不得通过修改脚本、注入参数、拼接 URL 等方式旁路调用白名单外的 Zoom 端点（如 `DELETE /users/{id}`、`PATCH /accounts/{id}` 等高风险端点）。\n- **强人类确认**：`create_meeting` 与 `delete_meeting` 在执行前必须获得用户显式确认；`delete_meeting` 命令还需附加 `--yes` 参数。\n\n## 凭证配置\n\n在 `.env` 文件中配置（**仅 chmod 600，不要提交到任何 Git 仓库**）：\n\n```env\nZOOM_ACCOUNT_ID=你的AccountID\nZOOM_CLIENT_ID=你的ClientID\nZOOM_CLIENT_SECRET=你的ClientSecret\nZOOM_USER_ID=你的用户邮箱或user_id\n```\n\n> ⚠️ 完整的安全规范见下一节 `## 凭证安全`。\n\n**Token 获取方式**：Server-to-Server OAuth，机器对机器，无需用户交互授权。\n\n## 凭证安全\n\n`.env` 中的 `ZOOM_CLIENT_SECRET` 是长期有效的账户级凭据，等同于账户管理员口令。**必须**遵守：\n\n- **加入 `.gitignore`**：本仓库 `.gitignore` 已包含 `.env`；同步确保 IDE、备份工具、文件同步（iCloud / Dropbox / OneDrive / 坚果云）不会自动上传该文件。\n- **限制文件权限**：`chmod 600 .env`；`scripts/zoom-s2s.py` 缓存的 `~/.zoom-s2s-token.json` 同样敏感（已自动 `chmod 600`），**不要**复制到剪贴板、聊天窗口、终端截图、报错工单、AI 对话上下文或第三方日志服务。\n- **不要在共享环境复用**：CI runner、公用跳板机、容器镜像、共享开发机中复用同一份凭据 ≈ 凭据公开。`Account ID + Client ID + Client Secret` 三元组可换得 1 小时有效的访问令牌。\n- **最小权限**：按 `## 最小权限配置建议` 表按需开启 Scope；不需要的 Action 不要勾选对应权限；`delete_meeting` 之外的写权限（`meeting:write:update`、`user:write:*`、`account:write:*`）默认不要开。\n- **独立 App**：为此 Skill 单独创建一个 Zoom Server-to-Server App，**不要**复用其他业务 App 的凭据；一旦泄露，旋转该 App 的凭据即可，不影响其他业务。\n- **凭据泄露应急**：在 Zoom Marketplace 删除该 App → 重新创建并轮换 `ACCOUNT_ID` / `CLIENT_ID` / `CLIENT_SECRET` / `USER_ID` 四项 → `rm -f ~/.zoom-s2s-token.json` 强制下次重新认证 → 复盘泄露路径。\n\n## 核心脚本\n\n`scripts/zoom-s2s.py` — 纯 Python，无外部依赖，兼容 Python 3.7+。\n\n```bash\ncd ~/.agents/skills/zoom-meeting-admin/scripts\n\n# 获取帮助\npython3 zoom-s2s.py help\n\n# 列出即将到来的会议\npython3 zoom-s2s.py list_meetings <user> <page_size> upcoming\n\n# 获取单个会议详情\npython3 zoom-s2s.py get_meeting <meeting_id>\n\n# 创建会议 (start_time: YYYY-MM-DDTHH:MM:SS)\npython3 zoom-s2s.py create_meeting \"<主题>\" \"<start_time>\" <时长分钟> [时区] [密码]\npython3 zoom-s2s.py create_meeting \"煎饼果子讨论会\" \"2026-05-05T10:00:00\" 60 Asia/Shanghai\n\n# 删除会议\npython3 zoom-s2s.py delete_meeting <meeting_id>\n\n# 获取云录像\npython3 zoom-s2s.py recordings <user> <page_size>\n\n# 获取用户信息\npython3 zoom-s2s.py get_user [user]\n\n# 列出账户下所有用户\npython3 zoom-s2s.py list_users [page_size]\n```\n\n## Token 缓存\n\n脚本自动缓存 Token 到 `~/.zoom-s2s-token.json`（有效期约 50 分钟），重复调用无需每次重新认证。\n\n## 常用操作快速参考\n\n| 操作 | 命令 |\n|------|------|\n| 列出最近5个会议 | `list_meetings <user> 5 upcoming` |\n| 列出最近10个历史会议 | `list_meetings <user> 10 past` |\n| 创建明天10点会议 | `create_meeting \"主题\" \"YYYY-MM-DDT10:00:00\" 60 Asia/Shanghai` |\n| 获取会议详情 | `get_meeting <id>` |\n| 删除会议 | `delete_meeting <id> --yes` |\n| 获取云录像 | `recordings <user> 10` |\n\n## 最小权限配置建议\n\n根据实际使用场景按需开通 scope，不需要的功能不要授权：\n\n| 功能 | 所需 Scope | 建议 |\n|------|-----------|------|\n| 列出会议 | `meeting:read:list_meetings` | ✅ 核心 |\n| 查看会议详情 | `meeting:read:meeting` | ✅ 核心 |\n| 创建会议 | `meeting:write:create` | 按需开启 |\n| **删除会议** | `meeting:write:delete` | ⚠️ 谨慎开启 |\n| **读取云录像** | `cloud_recording:read:list_user_recordings` | ⚠️ 谨慎开启 |\n| **列出账户用户** | `user:read:list_users` | ⚠️ 谨慎开启 |\n\n> 建议为此 Skill 单独创建一个 Zoom Server-to-Server App，不要复用已有 App 的凭证。\n\n## Agent 调用规范\n\n- **创建会议前**：向用户确认主题、时间、时长，再执行。\n- **删除会议前**：必须向用户明确展示会议信息并获得确认，命令需附加 `--yes` 参数。\n- **禁止超范围调用**：仅允许文档中列出的 Action，不得构造任意 Zoom REST API 请求。\n\n## 创建周期性会议\n\n创建 `type=8`（周期性会议）的 `recurrence` 参数说明：\n\n| recurrence.type | 说明 | 可用字段 | 是否可用 |\n|---|---|---|---|\n| 1 | 每日循环（Daily） | `end_date_time` 或 `count` | ✅ |\n| 2 | 每周循环（Weekly） | `weekly_days`（字符串）, `end_date_time` 或 `count` | ✅ |\n| 3 | 每月循环（Monthly） | `monthly_day` 或 `monthly_weeks` + `weekly_days` | ✅ |\n\n**⚠️ 关键避坑：`weekly_days` 必须是字符串，不是数组！**\n\n| 错误写法 | 正确写法 |\n|---------|---------|\n| `\"weekly_days\": [6]` | `\"weekly_days\": \"6\"` |\n| `\"weekly_days\": [\"6\"]` | `\"weekly_days\": \"6\"`（单日） |\n|  | `\"weekly_days\": \"6,0\"`（多日，周六+周日） |\n\n**weekly_days 取值**：1=周一 ~ 7=周日\n\n**示例**：创建 5月23日-24日（周六日）的周期性会议：\n```python\npayload = {\n    \"topic\": \"CSM公开课\",\n    \"type\": 8,\n    \"start_time\": \"2026-05-23T08:00:00\",\n    \"duration\": 540,\n    \"timezone\": \"Asia/Shanghai\",\n    \"recurrence\": {\n        \"type\": 2,\n        \"repeat_interval\": 1,\n        \"weekly_days\": \"6,0\",   # 周六+周日，字符串！\n        \"end_date_time\": \"2026-05-24T00:00:00Z\"\n    },\n    \"settings\": {\n        \"host_video\": True,\n        \"participant_video\": True,\n        \"join_before_host\": False,\n        \"mute_upon_entry\": False\n    }\n}\n```\n\n**多日示例**（周一+周三+周五）：\n```python\n\"weekly_days\": \"1,3,5\"\n```\n\n## 踩坑记录\n\n1. **scope 错误 (4711)**：某些 API（如 `get_user`）需要在 App 里开通对应 scope，又如 `list_meetings` 需要在 App 里开通 `meeting:read:list_meetings` 权限\n2. **Token 有效期**：Server-to-Server Token 有效期 1 小时，脚本自动刷新并缓存\n3. **用户 ID**：可用邮箱，也可用 `list_users` 查 user_id\n4. **`weekly_days` 必须为字符串**：Zoom API 要求 `weekly_days` 是 `\"6\"` 这样的字符串，而非 `[6]` 数组，传数组会报 300 错误\n\nFile v1.0.3:README.md\n\n# SKILL of Zoom Server-to-Server OAuth REST API\n\nManage and schedule Zoom meetings REST API directly via Server-to-Server OAuth — no VPS required, no MCP protocol needed.\n\n> EN | [中文](README.zh-cn.md)\n\n## Setup Steps\n\n1. Log in to https://marketplace.zoom.us/\n2. From the \"Develop\" dropdown, select \"build app\" and create an app of type `Server-to-Server OAuth`\n3. Add required OAuth Scopes\n4. Get the credentials\n5. Activate the app\n6. Invoke this SKILL in your AI agent\n\n## Credentials\n\nEdit the `.env` file with your Zoom Server-to-Server OAuth App credentials:\n\n```env\nZOOM_ACCOUNT_ID=yourAccountID\nZOOM_CLIENT_ID=yourClientID\nZOOM_CLIENT_SECRET=yourClientSecret\nZOOM_USER_ID=your_user_email_or_user_id\n```\n\n\n## Required OAuth Scopes\n\nEnable these in your Zoom Marketplace Server-to-Server OAuth App:\n\n| Scope | Purpose |\n|-------|---------|\n| `meeting:read:list_meetings` | List meetings |\n| `meeting:write:create` | Create meetings |\n| `meeting:write:delete` | Delete meetings |\n| `cloud_recording:read:list_user_recordings` | View cloud recordings |\n| `user:read:list_users` | List users |\n| `user:read:user` | Get user info |\n\n## Quick Start\n\n```bash\ncd ~/.agents/skills/zoom-s2s-oauth/scripts\n\n# List upcoming meetings\npython3 zoom-s2s.py list_meetings service@uperform.cn 5 upcoming\n\n# Create a meeting (start_time format: YYYY-MM-DDTHH:MM:SS)\npython3 zoom-s2s.py create_meeting \"Pancake Discussion\" \"2026-05-05T10:00:00\" 60 Asia/Shanghai\n\n# Get cloud recordings\npython3 zoom-s2s.py recordings service@uperform.cn 10\n```\n\n## Directory Structure\n\n```\nzoom-s2s-oauth/\n├── SKILL.md           # AI Agent invocation guide\n├── README.md          # This file\n├── README.zh-cn.md    # 中文版\n├── .env               # Credentials (do NOT commit to git!)\n└── scripts/\n    └── zoom-s2s.py    # Main script (pure Python3, no external dependencies)\n```\n\n\n## Comparison: MCP vs Server-to-Server REST\n\n| | MCP | Server-to-Server REST |\n|---|---|---|\n| Requires VPS | ✅ Yes (OAuth callback) | ❌ No |\n| Protocol | MCP (JSON-RPC) | Standard REST (pure Python, no deps) |\n| Token | User-Managed OAuth | Server-to-Server OAuth |\n| Complexity | High (proxy+OAuth) | Low (direct call) |\n| Features | Zoom MCP tools | All Zoom REST API |\n\nIf you only need core Zoom meeting/recording features, Server-to-Server REST is simpler.\n\nFile v1.0.3:_meta.json\n\n{\n  \"ownerId\": \"kn75w6500mvryv9p0k3czdfww982r5xh\",\n  \"slug\": \"zoom-meeting-admin\",\n  \"version\": \"1.0.3\",\n  \"publishedAt\": 1780668660160\n}\n\nFile v1.0.3:README.zh-cn.md\n\n# SKILL of Zoom Server-to-Server OAuth REST API \n\n用 Server-to-Server OAuth 直接调 Zoom meeting REST API，不需要 VPS，不需要 MCP 协议，管理和安排ZOOM会议。\n\n> [EN](README.md) | 中文\n\n## 配置步骤\n\n1. 需要先手动登录 https://marketplace.zoom.us/\n2. 在 \"Develop\" 下拉菜单选 \"build app\", 创建一个 `Server-to-Server OAuth`类型的APP\n3. 添加必要的OAuth Scope。\n4. 获取相关凭证密码\n5. 激活APP\n6. 在AI agent中调用此 SKILL\n\n## 凭证配置\n\n编辑 `.env` 文件，填入你的 Zoom Server-to-Server OAuth App 凭证：\n\n```env\nZOOM_ACCOUNT_ID=你的AccountID\nZOOM_CLIENT_ID=你的ClientID\nZOOM_CLIENT_SECRET=你的ClientSecret\nZOOM_USER_ID=你的用户邮箱或user_id\n```\n\n\n## 需要的 OAuth Scope\n\n在 Zoom Marketplace 你的 Server-to-Server OAuth App 里开通：\n\n| Scope | 用途 |\n|-------|------|\n| `meeting:read:list_meetings` | 列出会议 |\n| `meeting:write:create` | 创建会议 |\n| `meeting:write:delete` | 删除会议 |\n| `cloud_recording:read:list_user_recordings` | 查看云录像 |\n| `user:read:list_users` | 列出用户 |\n| `user:read:user` | 获取用户信息 |\n\n## 快速开始\n\n```bash\ncd ~/.agents/skills/zoom-s2s-oauth/scripts\n\n# 列出最近5个会议\npython3 zoom-s2s.py list_meetings service@uperform.cn 5 upcoming\n\n# 创建会议 (start_time 格式: YYYY-MM-DDTHH:MM:SS)\npython3 zoom-s2s.py create_meeting \"煎饼果子讨论会\" \"2026-05-05T10:00:00\" 60 Asia/Shanghai\n\n# 获取云录像\npython3 zoom-s2s.py recordings service@uperform.cn 10\n```\n\n## 目录结构\n\n```\nzoom-s2s-oauth/\n├── SKILL.md           # AI Agent 调用说明\n├── README.md          # 本文件\n├── .env               # 凭证配置 (不要提交到 git!)\n└── scripts/\n    └── zoom-s2s.py    # 主脚本 (纯 Python3，无外部依赖)\n```\n\n\n## 对比：MCP vs Server-to-Server REST\n\n| | MCP 方式 | Server-to-Server REST |\n|---|---|---|\n| 需要 VPS | ✅ 需要 (OAuth 回调) | ❌ 不需要 |\n| 协议 | MCP (JSON-RPC) | 标准 REST (Python 无外部依赖) |\n| Token | User-Managed OAuth | Server-to-Server OAuth |\n| 复杂度 | 高 (代理+OAuth) | 低 (直接调) |\n| 功能 | Zoom MCP 工具集 | 所有 Zoom REST API |\n\n如果你只需要调用 Zoom 会议/录像等核心功能，Server-to-Server REST 方式更简单。\n\nFile v1.0.3:skill-card.md\n\n## Description: <br>\nManage Zoom meetings, cloud recordings, and account users through a fixed set of Zoom Server-to-Server OAuth REST actions. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[mebusw](https://clawhub.ai/user/mebusw) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nZoom account administrators and operators use this skill from an agent to list, inspect, create, or delete scheduled meetings, query cloud recordings, and look up account users. It is intended for environments where a dedicated Zoom Server-to-Server OAuth app can be configured with only the scopes needed. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill uses Zoom Server-to-Server OAuth credentials and caches access tokens locally, so leaked files or logs could expose account-level access. <br>\nMitigation: Use a dedicated Zoom app, grant only required scopes, keep .env and ~/.zoom-s2s-token.json private with restrictive permissions, and verify .env is ignored by git. <br>\nRisk: Meeting creation and deletion can change live Zoom account state. <br>\nMitigation: Require explicit human approval before creating or deleting meetings, and keep delete permissions disabled unless they are needed. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/mebusw/zoom-meeting-admin) <br>\n- [Zoom Marketplace](https://marketplace.zoom.us/) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Shell commands, JSON, Configuration, Guidance] <br>\n**Output Format:** [Markdown guidance with shell commands and JSON API responses] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Requires Python 3.7+, network access to Zoom APIs, and local Zoom Server-to-Server OAuth credentials.] <br>\n\n## Skill Version(s): <br>\n1.0.3 (source: server-resolved release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.2: 6 files, 9938 bytes\n\nFiles: README.md (2363b), README.zh-cn.md (2326b), scripts/zoom-s2s.py (9766b), skill-card.md (2480b), SKILL.md (5283b), _meta.json (137b)\n\nFile v1.0.2:SKILL.md\n\n---\nname: zoom-meetin-admin\ndescription: Zoom Meeting REST API call skills. When users need to manage Zoom meetings, they can directly call the Zoom Meeting \"Server-to-Server OAuth\" REST API (without using the MCP protocol). Applicable scenarios are (1) List/view/search/create/delete Zoom meetings, (2) Query cloud recordings, (3) Get user information, (4) Any Zoom REST API call. Trigger words includes \"Zoom meeting\", \"Schedule a Zoom meeting\", \"View Zoom meeting\", \"List meetings\", \"Scheduled a meeting\".\n---\n\n# Zoom Server-to-Server OAuth REST API\n\n## 凭证配置\n\n在 `.env` 文件中配置并查看凭证：\n\n```env\nZOOM_ACCOUNT_ID=你的AccountID\nZOOM_CLIENT_ID=你的ClientID\nZOOM_CLIENT_SECRET=你的ClientSecret\nZOOM_USER_ID=你的用户邮箱或user_id\n```\n\n**Token 获取方式**：Server-to-Server OAuth，机器对机器，无需用户交互授权。\n\n## 核心脚本\n\n`scripts/zoom-s2s.py` — 纯 Python，无外部依赖，兼容 Python 3.7+。\n\n```bash\ncd ~/.agents/skills/zoom-s2s-oauth/scripts\n\n# 获取帮助\npython3 zoom-s2s.py help\n\n# 列出即将到来的会议\npython3 zoom-s2s.py list_meetings <user> <page_size> upcoming\n\n# 获取单个会议详情\npython3 zoom-s2s.py get_meeting <meeting_id>\n\n# 创建会议 (start_time: YYYY-MM-DDTHH:MM:SS)\npython3 zoom-s2s.py create_meeting \"<主题>\" \"<start_time>\" <时长分钟> [时区] [密码]\npython3 zoom-s2s.py create_meeting \"煎饼果子讨论会\" \"2026-05-05T10:00:00\" 60 Asia/Shanghai\n\n# 删除会议\npython3 zoom-s2s.py delete_meeting <meeting_id>\n\n# 获取云录像\npython3 zoom-s2s.py recordings <user> <page_size>\n\n# 获取用户信息\npython3 zoom-s2s.py get_user [user]\n\n# 列出账户下所有用户\npython3 zoom-s2s.py list_users [page_size]\n```\n\n## Token 缓存\n\n脚本自动缓存 Token 到 `~/.zoom-s2s-token.json`（有效期约 50 分钟），重复调用无需每次重新认证。\n\n## 常用操作快速参考\n\n| 操作 | 命令 |\n|------|------|\n| 列出最近5个会议 | `list_meetings <user> 5 upcoming` |\n| 列出最近10个历史会议 | `list_meetings <user> 10 past` |\n| 创建明天10点会议 | `create_meeting \"主题\" \"YYYY-MM-DDT10:00:00\" 60 Asia/Shanghai` |\n| 获取会议详情 | `get_meeting <id>` |\n| 删除会议 | `delete_meeting <id> --yes` |\n| 获取云录像 | `recordings <user> 10` |\n\n## 最小权限配置建议\n\n根据实际使用场景按需开通 scope，不需要的功能不要授权：\n\n| 功能 | 所需 Scope | 建议 |\n|------|-----------|------|\n| 列出会议 | `meeting:read:list_meetings` | ✅ 核心 |\n| 查看会议详情 | `meeting:read:meeting` | ✅ 核心 |\n| 创建会议 | `meeting:write:create` | 按需开启 |\n| **删除会议** | `meeting:write:delete` | ⚠️ 谨慎开启 |\n| **读取云录像** | `cloud_recording:read:list_user_recordings` | ⚠️ 谨慎开启 |\n| **列出账户用户** | `user:read:list_users` | ⚠️ 谨慎开启 |\n\n> 建议为此 Skill 单独创建一个 Zoom Server-to-Server App，不要复用已有 App 的凭证。\n\n## Agent 调用规范\n\n- **创建会议前**：向用户确认主题、时间、时长，再执行。\n- **删除会议前**：必须向用户明确展示会议信息并获得确认，命令需附加 `--yes` 参数。\n- **禁止超范围调用**：仅允许文档中列出的 Action，不得构造任意 Zoom REST API 请求。\n\n## 创建周期性会议\n\n创建 `type=8`（周期性会议）的 `recurrence` 参数说明：\n\n| recurrence.type | 说明 | 可用字段 | 是否可用 |\n|---|---|---|---|\n| 1 | 每日循环（Daily） | `end_date_time` 或 `count` | ✅ |\n| 2 | 每周循环（Weekly） | `weekly_days`（字符串）, `end_date_time` 或 `count` | ✅ |\n| 3 | 每月循环（Monthly） | `monthly_day` 或 `monthly_weeks` + `weekly_days` | ✅ |\n\n**⚠️ 关键避坑：`weekly_days` 必须是字符串，不是数组！**\n\n| 错误写法 | 正确写法 |\n|---------|---------|\n| `\"weekly_days\": [6]` | `\"weekly_days\": \"6\"` |\n| `\"weekly_days\": [\"6\"]` | `\"weekly_days\": \"6\"`（单日） |\n|  | `\"weekly_days\": \"6,0\"`（多日，周六+周日） |\n\n**weekly_days 取值**：1=周一 ~ 7=周日\n\n**示例**：创建 5月23日-24日（周六日）的周期性会议：\n```python\npayload = {\n    \"topic\": \"CSM公开课\",\n    \"type\": 8,\n    \"start_time\": \"2026-05-23T08:00:00\",\n    \"duration\": 540,\n    \"timezone\": \"Asia/Shanghai\",\n    \"recurrence\": {\n        \"type\": 2,\n        \"repeat_interval\": 1,\n        \"weekly_days\": \"6,0\",   # 周六+周日，字符串！\n        \"end_date_time\": \"2026-05-24T00:00:00Z\"\n    },\n    \"settings\": {\n        \"host_video\": True,\n        \"participant_video\": True,\n        \"join_before_host\": False,\n        \"mute_upon_entry\": False\n    }\n}\n```\n\n**多日示例**（周一+周三+周五）：\n```python\n\"weekly_days\": \"1,3,5\"\n```\n\n## 踩坑记录\n\n1. **scope 错误 (4711)**：某些 API（如 `get_user`）需要在 App 里开通对应 scope，又如 `list_meetings` 需要在 App 里开通 `meeting:read:list_meetings` 权限\n2. **Token 有效期**：Server-to-Server Token 有效期 1 小时，脚本自动刷新并缓存\n3. **用户 ID**：可用邮箱，也可用 `list_users` 查 user_id\n4. **`weekly_days` 必须为字符串**：Zoom API 要求 `weekly_days` 是 `\"6\"` 这样的字符串，而非 `[6]` 数组，传数组会报 300 错误\n\nFile v1.0.2:README.md\n\n# SKILL of Zoom Server-to-Server OAuth REST API\n\nManage and schedule Zoom meetings REST API directly via Server-to-Server OAuth — no VPS required, no MCP protocol needed.\n\n> EN | [中文](README.zh-cn.md)\n\n## Setup Steps\n\n1. Log in to https://marketplace.zoom.us/\n2. From the \"Develop\" dropdown, select \"build app\" and create an app of type `Server-to-Server OAuth`\n3. Add required OAuth Scopes\n4. Get the credentials\n5. Activate the app\n6. Invoke this SKILL in your AI agent\n\n## Credentials\n\nEdit the `.env` file with your Zoom Server-to-Server OAuth App credentials:\n\n```env\nZOOM_ACCOUNT_ID=yourAccountID\nZOOM_CLIENT_ID=yourClientID\nZOOM_CLIENT_SECRET=yourClientSecret\nZOOM_USER_ID=your_user_email_or_user_id\n```\n\n\n## Required OAuth Scopes\n\nEnable these in your Zoom Marketplace Server-to-Server OAuth App:\n\n| Scope | Purpose |\n|-------|---------|\n| `meeting:read:list_meetings` | List meetings |\n| `meeting:write:create` | Create meetings |\n| `meeting:write:delete` | Delete meetings |\n| `cloud_recording:read:list_user_recordings` | View cloud recordings |\n| `user:read:list_users` | List users |\n| `user:read:user` | Get user info |\n\n## Quick Start\n\n```bash\ncd ~/.agents/skills/zoom-s2s-oauth/scripts\n\n# List upcoming meetings\npython3 zoom-s2s.py list_meetings service@uperform.cn 5 upcoming\n\n# Create a meeting (start_time format: YYYY-MM-DDTHH:MM:SS)\npython3 zoom-s2s.py create_meeting \"Pancake Discussion\" \"2026-05-05T10:00:00\" 60 Asia/Shanghai\n\n# Get cloud recordings\npython3 zoom-s2s.py recordings service@uperform.cn 10\n```\n\n## Directory Structure\n\n```\nzoom-s2s-oauth/\n├── SKILL.md           # AI Agent invocation guide\n├── README.md          # This file\n├── README.zh-cn.md    # 中文版\n├── .env               # Credentials (do NOT commit to git!)\n└── scripts/\n    └── zoom-s2s.py    # Main script (pure Python3, no external dependencies)\n```\n\n\n## Comparison: MCP vs Server-to-Server REST\n\n| | MCP | Server-to-Server REST |\n|---|---|---|\n| Requires VPS | ✅ Yes (OAuth callback) | ❌ No |\n| Protocol | MCP (JSON-RPC) | Standard REST (pure Python, no deps) |\n| Token | User-Managed OAuth | Server-to-Server OAuth |\n| Complexity | High (proxy+OAuth) | Low (direct call) |\n| Features | Zoom MCP tools | All Zoom REST API |\n\nIf you only need core Zoom meeting/recording features, Server-to-Server REST is simpler.\n\nFile v1.0.2:_meta.json\n\n{\n  \"ownerId\": \"kn75w6500mvryv9p0k3czdfww982r5xh\",\n  \"slug\": \"zoom-meeting-admin\",\n  \"version\": \"1.0.2\",\n  \"publishedAt\": 1779248776227\n}\n\nFile v1.0.2:README.zh-cn.md\n\n# SKILL of Zoom Server-to-Server OAuth REST API \n\n用 Server-to-Server OAuth 直接调 Zoom meeting REST API，不需要 VPS，不需要 MCP 协议，管理和安排ZOOM会议。\n\n> [EN](README.md) | 中文\n\n## 配置步骤\n\n1. 需要先手动登录 https://marketplace.zoom.us/\n2. 在 \"Develop\" 下拉菜单选 \"build app\", 创建一个 `Server-to-Server OAuth`类型的APP\n3. 添加必要的OAuth Scope。\n4. 获取相关凭证密码\n5. 激活APP\n6. 在AI agent中调用此 SKILL\n\n## 凭证配置\n\n编辑 `.env` 文件，填入你的 Zoom Server-to-Server OAuth App 凭证：\n\n```env\nZOOM_ACCOUNT_ID=你的AccountID\nZOOM_CLIENT_ID=你的ClientID\nZOOM_CLIENT_SECRET=你的ClientSecret\nZOOM_USER_ID=你的用户邮箱或user_id\n```\n\n\n## 需要的 OAuth Scope\n\n在 Zoom Marketplace 你的 Server-to-Server OAuth App 里开通：\n\n| Scope | 用途 |\n|-------|------|\n| `meeting:read:list_meetings` | 列出会议 |\n| `meeting:write:create` | 创建会议 |\n| `meeting:write:delete` | 删除会议 |\n| `cloud_recording:read:list_user_recordings` | 查看云录像 |\n| `user:read:list_users` | 列出用户 |\n| `user:read:user` | 获取用户信息 |\n\n## 快速开始\n\n```bash\ncd ~/.agents/skills/zoom-s2s-oauth/scripts\n\n# 列出最近5个会议\npython3 zoom-s2s.py list_meetings service@uperform.cn 5 upcoming\n\n# 创建会议 (start_time 格式: YYYY-MM-DDTHH:MM:SS)\npython3 zoom-s2s.py create_meeting \"煎饼果子讨论会\" \"2026-05-05T10:00:00\" 60 Asia/Shanghai\n\n# 获取云录像\npython3 zoom-s2s.py recordings service@uperform.cn 10\n```\n\n## 目录结构\n\n```\nzoom-s2s-oauth/\n├── SKILL.md           # AI Agent 调用说明\n├── README.md          # 本文件\n├── .env               # 凭证配置 (不要提交到 git!)\n└── scripts/\n    └── zoom-s2s.py    # 主脚本 (纯 Python3，无外部依赖)\n```\n\n\n## 对比：MCP vs Server-to-Server REST\n\n| | MCP 方式 | Server-to-Server REST |\n|---|---|---|\n| 需要 VPS | ✅ 需要 (OAuth 回调) | ❌ 不需要 |\n| 协议 | MCP (JSON-RPC) | 标准 REST (Python 无外部依赖) |\n| Token | User-Managed OAuth | Server-to-Server OAuth |\n| 复杂度 | 高 (代理+OAuth) | 低 (直接调) |\n| 功能 | Zoom MCP 工具集 | 所有 Zoom REST API |\n\n如果你只需要调用 Zoom 会议/录像等核心功能，Server-to-Server REST 方式更简单。\n\nFile v1.0.2:skill-card.md\n\n## Description: <br>\nZoom Meeting REST API call skills. When users need to manage Zoom meetings, they can directly call the Zoom Meeting \"Server-to-Server OAuth\" REST API (without using the MCP protocol). <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[mebusw](https://clawhub.ai/user/mebusw) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers, operators, and assistants use this skill to list, inspect, create, and delete Zoom meetings, query cloud recordings, and retrieve Zoom user information through Zoom Server-to-Server OAuth. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill requires sensitive Zoom Server-to-Server OAuth credentials and account-level API access. <br>\nMitigation: Use a dedicated Zoom Server-to-Server app, grant only the required scopes, protect the .env file, and rotate credentials if the environment is shared or exposed. <br>\nRisk: Create, delete, recording, and user-data operations can change or expose Zoom account data. <br>\nMitigation: Require explicit user confirmation before create/delete or recording/user-data requests and review the exact operation before execution. <br>\nRisk: The access token is cached locally for reuse. <br>\nMitigation: Remove the cached token when work is complete or when the host environment is shared, transferred, or suspected of exposure. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/mebusw/zoom-meeting-admin) <br>\n- [Zoom Marketplace](https://marketplace.zoom.us/) <br>\n- [Zoom OAuth token endpoint](https://zoom.us/oauth/token) <br>\n- [Zoom REST API base endpoint](https://api.zoom.us/v2) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [guidance, shell commands, configuration, code, API calls] <br>\n**Output Format:** [Markdown guidance with inline shell commands and JSON API responses] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Requires Zoom Server-to-Server OAuth credentials in a local .env file and may cache an access token in the user's home directory.] <br>\n\n## Skill Version(s): <br>\n1.0.2 (source: server release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.1: 5 files, 8002 bytes\n\nFiles: README.md (2363b), README.zh-cn.md (2326b), scripts/zoom-s2s.py (9766b), SKILL.md (3685b), _meta.json (137b)\n\nFile v1.0.1:SKILL.md\n\n---\nname: zoom-meetin-admin\ndescription: Zoom Meeting REST API call skills. When users need to manage Zoom meetings, they can directly call the Zoom Meeting \"Server-to-Server OAuth\" REST API (without using the MCP protocol). Applicable scenarios are (1) List/view/search/create/delete Zoom meetings, (2) Query cloud recordings, (3) Get user information, (4) Any Zoom REST API call. Trigger words includes \"Zoom meeting\", \"Schedule a Zoom meeting\", \"View Zoom meeting\", \"List meetings\", \"Scheduled a meeting\".\n---\n\n# Zoom Server-to-Server OAuth REST API\n\n## 凭证配置\n\n在 `.env` 文件中配置并查看凭证：\n\n```env\nZOOM_ACCOUNT_ID=你的AccountID\nZOOM_CLIENT_ID=你的ClientID\nZOOM_CLIENT_SECRET=你的ClientSecret\nZOOM_USER_ID=你的用户邮箱或user_id\n```\n\n**Token 获取方式**：Server-to-Server OAuth，机器对机器，无需用户交互授权。\n\n## 核心脚本\n\n`scripts/zoom-s2s.py` — 纯 Python，无外部依赖，兼容 Python 3.7+。\n\n```bash\ncd ~/.agents/skills/zoom-s2s-oauth/scripts\n\n# 获取帮助\npython3 zoom-s2s.py help\n\n# 列出即将到来的会议\npython3 zoom-s2s.py list_meetings <user> <page_size> upcoming\n\n# 获取单个会议详情\npython3 zoom-s2s.py get_meeting <meeting_id>\n\n# 创建会议 (start_time: YYYY-MM-DDTHH:MM:SS)\npython3 zoom-s2s.py create_meeting \"<主题>\" \"<start_time>\" <时长分钟> [时区] [密码]\npython3 zoom-s2s.py create_meeting \"煎饼果子讨论会\" \"2026-05-05T10:00:00\" 60 Asia/Shanghai\n\n# 删除会议\npython3 zoom-s2s.py delete_meeting <meeting_id>\n\n# 获取云录像\npython3 zoom-s2s.py recordings <user> <page_size>\n\n# 获取用户信息\npython3 zoom-s2s.py get_user [user]\n\n# 列出账户下所有用户\npython3 zoom-s2s.py list_users [page_size]\n```\n\n## Token 缓存\n\n脚本自动缓存 Token 到 `~/.zoom-s2s-token.json`（有效期约 50 分钟），重复调用无需每次重新认证。\n\n## 常用操作快速参考\n\n| 操作 | 命令 |\n|------|------|\n| 列出最近5个会议 | `list_meetings <user> 5 upcoming` |\n| 列出最近10个历史会议 | `list_meetings <user> 10 past` |\n| 创建明天10点会议 | `create_meeting \"主题\" \"YYYY-MM-DDT10:00:00\" 60 Asia/Shanghai` |\n| 获取会议详情 | `get_meeting <id>` |\n| 删除会议 | `delete_meeting <id> --yes` |\n| 获取云录像 | `recordings <user> 10` |\n\n## 最小权限配置建议\n\n根据实际使用场景按需开通 scope，不需要的功能不要授权：\n\n| 功能 | 所需 Scope | 建议 |\n|------|-----------|------|\n| 列出会议 | `meeting:read:list_meetings` | ✅ 核心 |\n| 查看会议详情 | `meeting:read:meeting` | ✅ 核心 |\n| 创建会议 | `meeting:write:create` | 按需开启 |\n| **删除会议** | `meeting:write:delete` | ⚠️ 谨慎开启 |\n| **读取云录像** | `cloud_recording:read:list_user_recordings` | ⚠️ 谨慎开启 |\n| **列出账户用户** | `user:read:list_users` | ⚠️ 谨慎开启 |\n\n> 建议为此 Skill 单独创建一个 Zoom Server-to-Server App，不要复用已有 App 的凭证。\n\n## Agent 调用规范\n\n- **创建会议前**：向用户确认主题、时间、时长，再执行。\n- **删除会议前**：必须向用户明确展示会议信息并获得确认，命令需附加 `--yes` 参数。\n- **禁止超范围调用**：仅允许文档中列出的 Action，不得构造任意 Zoom REST API 请求。\n\n## 踩坑记录\n\n1. **scope 错误 (4711)**：某些 API（如 `get_user`）需要在 App 里开通对应 scope，又如 `list_meetings` 需要在 App 里开通 `meeting:read:list_meetings` 权限\n2. **Token 有效期**：Server-to-Server Token 有效期 1 小时，脚本自动刷新并缓存\n3. **用户 ID**：可用邮箱，也可用 `list_users` 查 user_id\n\nFile v1.0.1:README.md\n\n# SKILL of Zoom Server-to-Server OAuth REST API\n\nManage and schedule Zoom meetings REST API directly via Server-to-Server OAuth — no VPS required, no MCP protocol needed.\n\n> EN | [中文](README.zh-cn.md)\n\n## Setup Steps\n\n1. Log in to https://marketplace.zoom.us/\n2. From the \"Develop\" dropdown, select \"build app\" and create an app of type `Server-to-Server OAuth`\n3. Add required OAuth Scopes\n4. Get the credentials\n5. Activate the app\n6. Invoke this SKILL in your AI agent\n\n## Credentials\n\nEdit the `.env` file with your Zoom Server-to-Server OAuth App credentials:\n\n```env\nZOOM_ACCOUNT_ID=yourAccountID\nZOOM_CLIENT_ID=yourClientID\nZOOM_CLIENT_SECRET=yourClientSecret\nZOOM_USER_ID=your_user_email_or_user_id\n```\n\n\n## Required OAuth Scopes\n\nEnable these in your Zoom Marketplace Server-to-Server OAuth App:\n\n| Scope | Purpose |\n|-------|---------|\n| `meeting:read:list_meetings` | List meetings |\n| `meeting:write:create` | Create meetings |\n| `meeting:write:delete` | Delete meetings |\n| `cloud_recording:read:list_user_recordings` | View cloud recordings |\n| `user:read:list_users` | List users |\n| `user:read:user` | Get user info |\n\n## Quick Start\n\n```bash\ncd ~/.agents/skills/zoom-s2s-oauth/scripts\n\n# List upcoming meetings\npython3 zoom-s2s.py list_meetings service@uperform.cn 5 upcoming\n\n# Create a meeting (start_time format: YYYY-MM-DDTHH:MM:SS)\npython3 zoom-s2s.py create_meeting \"Pancake Discussion\" \"2026-05-05T10:00:00\" 60 Asia/Shanghai\n\n# Get cloud recordings\npython3 zoom-s2s.py recordings service@uperform.cn 10\n```\n\n## Directory Structure\n\n```\nzoom-s2s-oauth/\n├── SKILL.md           # AI Agent invocation guide\n├── README.md          # This file\n├── README.zh-cn.md    # 中文版\n├── .env               # Credentials (do NOT commit to git!)\n└── scripts/\n    └── zoom-s2s.py    # Main script (pure Python3, no external dependencies)\n```\n\n\n## Comparison: MCP vs Server-to-Server REST\n\n| | MCP | Server-to-Server REST |\n|---|---|---|\n| Requires VPS | ✅ Yes (OAuth callback) | ❌ No |\n| Protocol | MCP (JSON-RPC) | Standard REST (pure Python, no deps) |\n| Token | User-Managed OAuth | Server-to-Server OAuth |\n| Complexity | High (proxy+OAuth) | Low (direct call) |\n| Features | Zoom MCP tools | All Zoom REST API |\n\nIf you only need core Zoom meeting/recording features, Server-to-Server REST is simpler.\n\nFile v1.0.1:_meta.json\n\n{\n  \"ownerId\": \"kn75w6500mvryv9p0k3czdfww982r5xh\",\n  \"slug\": \"zoom-meeting-admin\",\n  \"version\": \"1.0.1\",\n  \"publishedAt\": 1777962973625\n}\n\nFile v1.0.1:README.zh-cn.md\n\n# SKILL of Zoom Server-to-Server OAuth REST API \n\n用 Server-to-Server OAuth 直接调 Zoom meeting REST API，不需要 VPS，不需要 MCP 协议，管理和安排ZOOM会议。\n\n> [EN](README.md) | 中文\n\n## 配置步骤\n\n1. 需要先手动登录 https://marketplace.zoom.us/\n2. 在 \"Develop\" 下拉菜单选 \"build app\", 创建一个 `Server-to-Server OAuth`类型的APP\n3. 添加必要的OAuth Scope。\n4. 获取相关凭证密码\n5. 激活APP\n6. 在AI agent中调用此 SKILL\n\n## 凭证配置\n\n编辑 `.env` 文件，填入你的 Zoom Server-to-Server OAuth App 凭证：\n\n```env\nZOOM_ACCOUNT_ID=你的AccountID\nZOOM_CLIENT_ID=你的ClientID\nZOOM_CLIENT_SECRET=你的ClientSecret\nZOOM_USER_ID=你的用户邮箱或user_id\n```\n\n\n## 需要的 OAuth Scope\n\n在 Zoom Marketplace 你的 Server-to-Server OAuth App 里开通：\n\n| Scope | 用途 |\n|-------|------|\n| `meeting:read:list_meetings` | 列出会议 |\n| `meeting:write:create` | 创建会议 |\n| `meeting:write:delete` | 删除会议 |\n| `cloud_recording:read:list_user_recordings` | 查看云录像 |\n| `user:read:list_users` | 列出用户 |\n| `user:read:user` | 获取用户信息 |\n\n## 快速开始\n\n```bash\ncd ~/.agents/skills/zoom-s2s-oauth/scripts\n\n# 列出最近5个会议\npython3 zoom-s2s.py list_meetings service@uperform.cn 5 upcoming\n\n# 创建会议 (start_time 格式: YYYY-MM-DDTHH:MM:SS)\npython3 zoom-s2s.py create_meeting \"煎饼果子讨论会\" \"2026-05-05T10:00:00\" 60 Asia/Shanghai\n\n# 获取云录像\npython3 zoom-s2s.py recordings service@uperform.cn 10\n```\n\n## 目录结构\n\n```\nzoom-s2s-oauth/\n├── SKILL.md           # AI Agent 调用说明\n├── README.md          # 本文件\n├── .env               # 凭证配置 (不要提交到 git!)\n└── scripts/\n    └── zoom-s2s.py    # 主脚本 (纯 Python3，无外部依赖)\n```\n\n\n## 对比：MCP vs Server-to-Server REST\n\n| | MCP 方式 | Server-to-Server REST |\n|---|---|---|\n| 需要 VPS | ✅ 需要 (OAuth 回调) | ❌ 不需要 |\n| 协议 | MCP (JSON-RPC) | 标准 REST (Python 无外部依赖) |\n| Token | User-Managed OAuth | Server-to-Server OAuth |\n| 复杂度 | 高 (代理+OAuth) | 低 (直接调) |\n| 功能 | Zoom MCP 工具集 | 所有 Zoom REST API |\n\n如果你只需要调用 Zoom 会议/录像等核心功能，Server-to-Server REST 方式更简单。\n\nArchive v1.0.0: 5 files, 7378 bytes\n\nFiles: README.md (2363b), README.zh-cn.md (2326b), scripts/zoom-s2s.py (9311b), SKILL.md (2655b), _meta.json (137b)\n\nFile v1.0.0:SKILL.md\n\n---\nname: zoom-meetin-admin\ndescription: Zoom Meeting REST API call skills. When users need to manage Zoom meetings, they can directly call the Zoom Meeting \"Server-to-Server OAuth\" REST API (without using the MCP protocol). Applicable scenarios are (1) List/view/search/create/delete Zoom meetings, (2) Query cloud recordings, (3) Get user information, (4) Any Zoom REST API call. Trigger words includes \"Zoom meeting\", \"Schedule a Zoom meeting\", \"Zoom meeting\", \"List meetings\", \"Scheduled a meeting\".\n---\n\n# Zoom Server-to-Server OAuth REST API\n\n## 凭证配置\n\n在 `.env` 文件中配置并查看凭证：\n\n```env\nZOOM_ACCOUNT_ID=你的AccountID\nZOOM_CLIENT_ID=你的ClientID\nZOOM_CLIENT_SECRET=你的ClientSecret\nZOOM_USER_ID=你的用户邮箱或user_id\n```\n\n**Token 获取方式**：Server-to-Server OAuth，机器对机器，无需用户交互授权。\n\n## 核心脚本\n\n`scripts/zoom-s2s.py` — 纯 Python，无外部依赖，兼容 Python 3.7+。\n\n```bash\ncd ~/.agents/skills/zoom-s2s-oauth/scripts\n\n# 获取帮助\npython3 zoom-s2s.py help\n\n# 列出即将到来的会议\npython3 zoom-s2s.py list_meetings <user> <page_size> upcoming\n\n# 获取单个会议详情\npython3 zoom-s2s.py get_meeting <meeting_id>\n\n# 创建会议 (start_time: YYYY-MM-DDTHH:MM:SS)\npython3 zoom-s2s.py create_meeting \"<主题>\" \"<start_time>\" <时长分钟> [时区] [密码]\npython3 zoom-s2s.py create_meeting \"煎饼果子讨论会\" \"2026-05-05T10:00:00\" 60 Asia/Shanghai\n\n# 删除会议\npython3 zoom-s2s.py delete_meeting <meeting_id>\n\n# 获取云录像\npython3 zoom-s2s.py recordings <user> <page_size>\n\n# 获取用户信息\npython3 zoom-s2s.py get_user [user]\n\n# 列出账户下所有用户\npython3 zoom-s2s.py list_users [page_size]\n```\n\n## Token 缓存\n\n脚本自动缓存 Token 到 `~/.zoom-s2s-token.json`（有效期约 50 分钟），重复调用无需每次重新认证。\n\n## 常用操作快速参考\n\n| 操作 | 命令 |\n|------|------|\n| 列出最近5个会议 | `list_meetings <user> 5 upcoming` |\n| 列出最近10个历史会议 | `list_meetings <user> 10 past` |\n| 创建明天10点会议 | `create_meeting \"主题\" \"YYYY-MM-DDT10:00:00\" 60 Asia/Shanghai` |\n| 获取会议详情 | `get_meeting <id>` |\n| 删除会议 | `delete_meeting <id>` |\n| 获取云录像 | `recordings <user> 10` |\n\n## 踩坑记录\n\n1. **scope 错误 (4711)**：某些 API（如 `get_user`）需要在 App 里开通对应 scope，又如 `list_meetings` 需要在 App 里开通 `meeting:read:list_meetings` 权限\n2. **Token 有效期**：Server-to-Server Token 有效期 1 小时，脚本自动刷新并缓存\n3. **用户 ID**：可用邮箱，也可用 `list_users` 查 user_id\n\nFile v1.0.0:README.md\n\n# SKILL of Zoom Server-to-Server OAuth REST API\n\nManage and schedule Zoom meetings REST API directly via Server-to-Server OAuth — no VPS required, no MCP protocol needed.\n\n> EN | [中文](README.zh-cn.md)\n\n## Setup Steps\n\n1. Log in to https://marketplace.zoom.us/\n2. From the \"Develop\" dropdown, select \"build app\" and create an app of type `Server-to-Server OAuth`\n3. Add required OAuth Scopes\n4. Get the credentials\n5. Activate the app\n6. Invoke this SKILL in your AI agent\n\n## Credentials\n\nEdit the `.env` file with your Zoom Server-to-Server OAuth App credentials:\n\n```env\nZOOM_ACCOUNT_ID=yourAccountID\nZOOM_CLIENT_ID=yourClientID\nZOOM_CLIENT_SECRET=yourClientSecret\nZOOM_USER_ID=your_user_email_or_user_id\n```\n\n\n## Required OAuth Scopes\n\nEnable these in your Zoom Marketplace Server-to-Server OAuth App:\n\n| Scope | Purpose |\n|-------|---------|\n| `meeting:read:list_meetings` | List meetings |\n| `meeting:write:create` | Create meetings |\n| `meeting:write:delete` | Delete meetings |\n| `cloud_recording:read:list_user_recordings` | View cloud recordings |\n| `user:read:list_users` | List users |\n| `user:read:user` | Get user info |\n\n## Quick Start\n\n```bash\ncd ~/.agents/skills/zoom-s2s-oauth/scripts\n\n# List upcoming meetings\npython3 zoom-s2s.py list_meetings service@uperform.cn 5 upcoming\n\n# Create a meeting (start_time format: YYYY-MM-DDTHH:MM:SS)\npython3 zoom-s2s.py create_meeting \"Pancake Discussion\" \"2026-05-05T10:00:00\" 60 Asia/Shanghai\n\n# Get cloud recordings\npython3 zoom-s2s.py recordings service@uperform.cn 10\n```\n\n## Directory Structure\n\n```\nzoom-s2s-oauth/\n├── SKILL.md           # AI Agent invocation guide\n├── README.md          # This file\n├── README.zh-cn.md    # 中文版\n├── .env               # Credentials (do NOT commit to git!)\n└── scripts/\n    └── zoom-s2s.py    # Main script (pure Python3, no external dependencies)\n```\n\n\n## Comparison: MCP vs Server-to-Server REST\n\n| | MCP | Server-to-Server REST |\n|---|---|---|\n| Requires VPS | ✅ Yes (OAuth callback) | ❌ No |\n| Protocol | MCP (JSON-RPC) | Standard REST (pure Python, no deps) |\n| Token | User-Managed OAuth | Server-to-Server OAuth |\n| Complexity | High (proxy+OAuth) | Low (direct call) |\n| Features | Zoom MCP tools | All Zoom REST API |\n\nIf you only need core Zoom meeting/recording features, Server-to-Server REST is simpler.\n\nFile v1.0.0:_meta.json\n\n{\n  \"ownerId\": \"kn75w6500mvryv9p0k3czdfww982r5xh\",\n  \"slug\": \"zoom-meeting-admin\",\n  \"version\": \"1.0.0\",\n  \"publishedAt\": 1777903059575\n}\n\nFile v1.0.0:README.zh-cn.md\n\n# SKILL of Zoom Server-to-Server OAuth REST API \n\n用 Server-to-Server OAuth 直接调 Zoom meeting REST API，不需要 VPS，不需要 MCP 协议，管理和安排ZOOM会议。\n\n> [EN](README.md) | 中文\n\n## 配置步骤\n\n1. 需要先手动登录 https://marketplace.zoom.us/\n2. 在 \"Develop\" 下拉菜单选 \"build app\", 创建一个 `Server-to-Server OAuth`类型的APP\n3. 添加必要的OAuth Scope。\n4. 获取相关凭证密码\n5. 激活APP\n6. 在AI agent中调用此 SKILL\n\n## 凭证配置\n\n编辑 `.env` 文件，填入你的 Zoom Server-to-Server OAuth App 凭证：\n\n```env\nZOOM_ACCOUNT_ID=你的AccountID\nZOOM_CLIENT_ID=你的ClientID\nZOOM_CLIENT_SECRET=你的ClientSecret\nZOOM_USER_ID=你的用户邮箱或user_id\n```\n\n\n## 需要的 OAuth Scope\n\n在 Zoom Marketplace 你的 Server-to-Server OAuth App 里开通：\n\n| Scope | 用途 |\n|-------|------|\n| `meeting:read:list_meetings` | 列出会议 |\n| `meeting:write:create` | 创建会议 |\n| `meeting:write:delete` | 删除会议 |\n| `cloud_recording:read:list_user_recordings` | 查看云录像 |\n| `user:read:list_users` | 列出用户 |\n| `user:read:user` | 获取用户信息 |\n\n## 快速开始\n\n```bash\ncd ~/.agents/skills/zoom-s2s-oauth/scripts\n\n# 列出最近5个会议\npython3 zoom-s2s.py list_meetings service@uperform.cn 5 upcoming\n\n# 创建会议 (start_time 格式: YYYY-MM-DDTHH:MM:SS)\npython3 zoom-s2s.py create_meeting \"煎饼果子讨论会\" \"2026-05-05T10:00:00\" 60 Asia/Shanghai\n\n# 获取云录像\npython3 zoom-s2s.py recordings service@uperform.cn 10\n```\n\n## 目录结构\n\n```\nzoom-s2s-oauth/\n├── SKILL.md           # AI Agent 调用说明\n├── README.md          # 本文件\n├── .env               # 凭证配置 (不要提交到 git!)\n└── scripts/\n    └── zoom-s2s.py    # 主脚本 (纯 Python3，无外部依赖)\n```\n\n\n## 对比：MCP vs Server-to-Server REST\n\n| | MCP 方式 | Server-to-Server REST |\n|---|---|---|\n| 需要 VPS | ✅ 需要 (OAuth 回调) | ❌ 不需要 |\n| 协议 | MCP (JSON-RPC) | 标准 REST (Python 无外部依赖) |\n| Token | User-Managed OAuth | Server-to-Server OAuth |\n| 复杂度 | 高 (代理+OAuth) | 低 (直接调) |\n| 功能 | Zoom MCP 工具集 | 所有 Zoom REST API |\n\n如果你只需要调用 Zoom 会议/录像等核心功能，Server-to-Server REST 方式更简单。","readmeExcerpt":"Skill: zoom-meeting-admin Owner: mebusw Summary: List, create, delete, and query Zoom meetings, cloud recordings, and account users via a fixed CLI (scripts/zoom-s2s.py, 7 whitelisted actions) using Server-to-Server OAuth. Use when the user asks to schedule, reschedule, cancel, find, or look up a Zoom meeting; set up a recurring Zoom; pull cloud recordings or past meeting metadata; or look up account users. Triggers ","codeSnippets":[],"executableExamples":[{"language":"env","snippet":"ZOOM_ACCOUNT_ID=你的AccountID\nZOOM_CLIENT_ID=你的ClientID\nZOOM_CLIENT_SECRET=你的ClientSecret\nZOOM_USER_ID=你的用户邮箱或user_id"},{"language":"bash","snippet":"# 调用前先 cd 到 scripts/ 目录（skill 根目录下的 scripts/ 子目录）\ncd scripts\n\n# 获取帮助\npython3 zoom-s2s.py help\n\n# 列出即将到来的会议\npython3 zoom-s2s.py list_meetings <user> <page_size> upcoming\n\n# 获取单个会议详情\npython3 zoom-s2s.py get_meeting <meeting_id>\n\n# 创建会议 (start_time: YYYY-MM-DDTHH:MM:SS)\npython3 zoom-s2s.py create_meeting \"<主题>\" \"<start_time>\" <时长分钟> [时区] [密码]\n# 创建周期性会议（每周一，7次，每次120分钟；weekly_days=\"2\" = Zoom 编码周一）\npython3 zoom-s2s.py create_meeting \"CSM公开课\" \"2026-05-23T08:00:00\" 120 Asia/Shanghai \"\" 2 1 2 7\npython3 zoom-s2s.py create_meeting \"煎饼果子讨论会\" \"2026-05-05T10:00:00\" 60 Asia/Shanghai\n\n# 删除会议\npython3 zoom-s2s.py delete_meeting <meeting_id>\n\n# 获取云录像\npython3 zoom-s2s.py recordings <user> <page_size>\n\n# 获取用户信息\npython3 zoom-s2s.py get_user [user]\n\n# 列出账户下所有用户\npython3 zoom-s2s.py list_users [page_size]"},{"language":"json","snippet":"{\n  \"id\": 85123456789,\n  \"topic\": \"每周一的产品同步\",\n  \"type\": 2,\n  \"start_time\": \"2026-08-24T20:00:00Z\",\n  \"duration\": 120,\n  \"timezone\": \"America/New_York\",\n  \"join_url\": \"https://us05web.zoom.us/j/85123456789?pwd=...\",\n  \"start_url\": \"https://us05web.zoom.us/s/85123456789?zak=...\",\n  \"password\": \"abc123\"\n}"},{"language":"bash","snippet":"python3 zoom-s2s.py create_meeting \"<主题>\" \"<start_time>\" <duration> [timezone] [password] \\\n  [recurrence_type] [repeat_interval] [weekly_days] [end_times] [end_date_time] \\\n  [monthly_day] [monthly_weeks]"},{"language":"bash","snippet":"python3 zoom-s2s.py create_meeting \"每周一的产品同步\" \\\n  \"2026-08-24T20:00:00\" 120 America/New_York \"\" 2 1 2 7\n# weekly_days=\"2\" = Zoom 编码 2 = 周一"},{"language":"bash","snippet":"python3 zoom-s2s.py create_meeting \"月度复盘\" \\\n  \"2026-08-15T10:00:00\" 60 Asia/Shanghai \"\" 3 1 15 12\n# positional: topic, start_time, duration, tz, password, type=3, repeat=1, weekly_days=15, end_times=12\n# 解释: monthly_day=\"15\"（每月 15 号）"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: zoom-meeting-admin\nallowed-tools: Bash(python3 zoom-s2s.py:*) Read\ncompatibility: Requires Python 3.7+; performs HTTPS calls to zoom.us and api.zoom.us (network); writes a token cache to ~/.zoom-s2s-token.json (auto chmod 600); reads ZOOM_ACCOUNT_ID / ZOOM_CLIENT_ID / ZOOM_CLIENT_SECRET / ZOOM_USER_ID from a local .env.\ndescription: List, create, delete, and query Zoom meetings, cloud recordings, and account users via a fixed CLI (scripts/zoom-s2s.py, 7 whitelisted actions) using Server-to-Server OAuth. Use when the user asks to schedule, reschedule, cancel, find, or look up a Zoom meeting; set up a recurring Zoom; pull cloud recordings or past meeting metadata; or look up account users. Triggers on phrases like \"Zoom meeting\", \"zoom 会议\", \"约 Zoom\", \"取消 Zoom\", \"录像\", \"schedule a Zoom\", \"cancel the meeting\", \"who's on the call\", \"云录制\". create_meeting requires explicit confirmation of topic, start_time, duration; delete_meeting requires --yes and visible confirmation. Agent must only invoke the 7 whitelisted CLI actions and must not modify the script, import internals, or call Zoom REST directly. Requires .env with ACCOUNT_ID/CLIENT_ID/CLIENT_SECRET/USER_ID. Documentation is in Chinese; outputs follow.\n---\n\n> ⚠️ **安全提示 — 凭证等同于账户管理员口令**\n>\n> 本 Skill 通过 `.env` 中的 `ZOOM_CLIENT_SECRET` 等 Server-to-Server OAuth 凭证访问 Zoom 账户。\n> `ACCOUNT_ID + CLIENT_ID + CLIENT_SECRET` 三元组可换取 1 小时有效的账户级访问令牌，**能够读取该账户下所有会议元数据、云录像，并执行删除等破坏性操作**。\n>\n> **使用前请先完整阅读 [`## 凭证安全`](#凭证安全)**，遵守 `.gitignore`、`chmod 600`、最小 scope、专用 App、泄露应急等要求。\n> 任何**修改脚本、import 内部函数、构造任意 payload 调用 `api_call`** 的尝试都构成越权，会被本文档明确禁止。\n\n# Zoom Server-to-Server OAuth REST API\n\n## 权限与约束\n\n本 Skill 通过 `scripts/zoom-s2s.py` 调用 Zoom Server-to-Server OAuth REST API，不实现\"通用 REST 代理\"。\n\n- **声明的工具**：`Bash(python3 zoom-s2s.py:*)`（仅执行本 skill 的 CLI 脚本）、`Read`（读取 SKILL.md、脚本源码、`.env.sample`、token cache 等）。\n- **网络访问**：向 `https://zoom.us/oauth/token` 与 `https://api.zoom.us/v2/*` 发起 HTTPS 请求，传输头包含 `Authorization: Bearer <token>`。\n- **文件写入**：在 `~/.zoom-s2s-token.json` 缓存访问令牌（已自动 `chmod 600`）。\n- **凭证读取**：从仓库根目录的 `.env` 读取 `ZOOM_ACCOUNT_ID` / `ZOOM_CLIENT_ID` / `ZOOM_CLIENT_SECRET` / `ZOOM_USER_ID`。\n- **允许的 Action（白名单）**——禁止构造任意 Zoom REST 请求或调用未列出的端点：\n  - 会议：`list_meetings` / `get_meeting` / `create_meeting` / `delete_meeting`\n  - 用户：`get_user` / `list_users`\n  - 录像：`recordings`\n- **越权防护**：脚本内部包含一个 `api_call` 函数供 CLI action 复用，但这是**私有实现细节，不是对外可调用的接口**。Agent 不得通过以下任何方式旁路调用白名单外的 Zoom 端点（如 `DELETE /users/{id}`、`PATCH /accounts/{id}` 等高风险端点）：\n  - 修改 `scripts/zoom-s2s.py`、新增 CLI action、暴露 `api_call`；\n  - `from zoom_s2s import api_call` 或以其他方式直接调用脚本内部函数；\n  - 在调用本 Skill 的同时**另起进程**用相同凭证调任意 Zoom REST API（如 `curl` 直接打 `api.zoom.us`）；\n  - 注入参数、拼接 URL、构造任意 JSON payload 绕过 CLI 校验逻辑。\n  脚本遵循\"最小暴露面\"原则：CLI 只暴露 7 个白名单 action，**任何其他调用路径都视为越权**。\n- **强人类确认**：`create_meeting` 与 `delete_meeting` 在执行前必须获得用户显式确认；`delete_meeting` 命令还需附加 `--yes` 参数。\n\n## 凭证配置\n\n在 `.env` 文件中配置（**仅 chmod 600，不要提交到任何 Git 仓库**）：\n\n```env\nZOOM_ACCOUNT_ID=你的AccountID\nZOOM"},{"path":"README.md","content":"# SKILL of Zoom Server-to-Server OAuth REST API\n\nManage and schedule Zoom meetings REST API directly via Server-to-Server OAuth — no VPS required, no MCP protocol needed.\n\n> EN | [中文](README.zh-cn.md)\n\n## Setup Steps\n\n1. Log in to https://marketplace.zoom.us/\n2. From the \"Develop\" dropdown, select \"build app\" and create an app of type `Server-to-Server OAuth`\n3. Add required OAuth Scopes\n4. Get the credentials\n5. Activate the app\n6. Invoke this SKILL in your AI agent\n\n## Credentials\n\n> ⚠️ **The `ZOOM_CLIENT_SECRET` in `.env` is equivalent to an account-admin password.** Anyone holding the `ACCOUNT_ID + CLIENT_ID + CLIENT_SECRET` triple can mint a 1-hour account-level access token that reads all meeting metadata, cloud recordings, and can delete meetings.\n>\n> - Never commit `.env` to git. Confirm your IDE, backup tools, and file-sync services (iCloud / Dropbox / OneDrive / Nutstore) are not auto-uploading it.\n> - `chmod 600 .env`. The token cache at `~/.zoom-s2s-token.json` is auto-set to `chmod 600` by the script.\n> - Use the **minimum scopes** you actually need (see table below). Do not enable `meeting:write:delete`, `cloud_recording:read:*`, or `user:read:list_users` unless required.\n> - Create a **dedicated** Server-to-Server App for this skill — do not reuse credentials from other business apps.\n> - If leaked: delete the App in Zoom Marketplace → re-create and rotate all four values → `rm -f ~/.zoom-s2s-token.json`.\n\nEdit the `.env` file with your Zoom Server-to-Server OAuth App credentials:\n\n```env\nZOOM_ACCOUNT_ID=yourAccountID\nZOOM_CLIENT_ID=yourClientID\nZOOM_CLIENT_SECRET=yourClientSecret\nZOOM_USER_ID=your_user_email_or_user_id\n```\n\n\n## Required OAuth Scopes\n\nEnable these in your Zoom Marketplace Server-to-Server OAuth App:\n\n| Scope | Purpose |\n|-------|---------|\n| `meeting:read:list_meetings` | List meetings |\n| `meeting:write:create` | Create meetings |\n| `meeting:write:delete` | Delete meetings |\n| `cloud_recording:read:list_user_recordings` | View cloud recordings |\n| `user:read:list_users` | List users |\n| `user:read:user` | Get user info |\n\n## Quick Start\n\n```bash\ncd ~/.agents/skills/zoom-s2s-oauth/scripts\n\n# List upcoming meetings\npython3 zoom-s2s.py list_meetings service@uperform.cn 5 upcoming\n\n# Create a meeting (start_time format: YYYY-MM-DDTHH:MM:SS)\npython3 zoom-s2s.py create_meeting \"Pancake Discussion\" \"2026-05-05T10:00:00\" 60 Asia/Shanghai\n\n# Get cloud recordings\npython3 zoom-s2s.py recordings service@uperform.cn 10\n```\n\n## Directory Structure\n\n```\nzoom-s2s-oauth/\n├── SKILL.md           # AI Agent invocation guide\n├── README.md          # This file\n├── README.zh-cn.md    # 中文版\n├── .env               # Credentials (do NOT commit to git!)\n└── scripts/\n    └── zoom-s2s.py    # Main script (pure Python3, no external dependencies)\n```\n\n\n## Comparison: MCP vs Server-to-Server REST\n\n| | MCP | Server-to-Server REST |\n|---|---|---|\n| Requires VPS | ✅ Yes (OAuth callback) | ❌ No |\n| Protocol | MCP (JSON-RPC) | Standard REST (pure Pyt"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn75w6500mvryv9p0k3czdfww982r5xh\",\n  \"slug\": \"zoom-meeting-admin\",\n  \"version\": \"1.0.6\",\n  \"publishedAt\": 1790477470935\n}"},{"path":"README.zh-cn.md","content":"# SKILL of Zoom Server-to-Server OAuth REST API \n\n用 Server-to-Server OAuth 直接调 Zoom meeting REST API，不需要 VPS，不需要 MCP 协议，管理和安排ZOOM会议。\n\n> [EN](README.md) | 中文\n\n## 配置步骤\n\n1. 需要先手动登录 https://marketplace.zoom.us/\n2. 在 \"Develop\" 下拉菜单选 \"build app\", 创建一个 `Server-to-Server OAuth`类型的APP\n3. 添加必要的OAuth Scope。\n4. 获取相关凭证密码\n5. 激活APP\n6. 在AI agent中调用此 SKILL\n\n## 凭证配置\n\n> ⚠️ **`.env` 中的 `ZOOM_CLIENT_SECRET` 等同于账户管理员口令。** 持有 `ACCOUNT_ID + CLIENT_ID + CLIENT_SECRET` 三元组即可换取 1 小时有效的账户级访问令牌，**能读取该账户下所有会议元数据、云录像，并执行删除等破坏性操作**。\n>\n> - 千万不要把 `.env` 提交到 git。确认你的 IDE、备份工具、文件同步服务（iCloud / Dropbox / OneDrive / 坚果云）没有自动上传该文件。\n> - `chmod 600 .env`。脚本缓存的 token 文件 `~/.zoom-s2s-token.json` 由脚本自动 `chmod 600`。\n> - **按需开通最小 scope**（见下表）。未用到的功能不要勾选对应权限；不要轻易开启 `meeting:write:delete`、`cloud_recording:read:*`、`user:read:list_users`。\n> - 为本 Skill **单独创建一个** Server-to-Server App，不要复用其他业务 App 的凭据。\n> - 一旦泄露：在 Zoom Marketplace 删除该 App → 重新创建并轮换四项值 → `rm -f ~/.zoom-s2s-token.json` 强制重新认证。\n\n编辑 `.env` 文件，填入你的 Zoom Server-to-Server OAuth App 凭证：\n\n```env\nZOOM_ACCOUNT_ID=你的AccountID\nZOOM_CLIENT_ID=你的ClientID\nZOOM_CLIENT_SECRET=你的ClientSecret\nZOOM_USER_ID=你的用户邮箱或user_id\n```\n\n\n## 需要的 OAuth Scope\n\n在 Zoom Marketplace 你的 Server-to-Server OAuth App 里开通：\n\n| Scope | 用途 |\n|-------|------|\n| `meeting:read:list_meetings` | 列出会议 |\n| `meeting:write:create` | 创建会议 |\n| `meeting:write:delete` | 删除会议 |\n| `cloud_recording:read:list_user_recordings` | 查看云录像 |\n| `user:read:list_users` | 列出用户 |\n| `user:read:user` | 获取用户信息 |\n\n## 快速开始\n\n```bash\ncd ~/.agents/skills/zoom-s2s-oauth/scripts\n\n# 列出最近5个会议\npython3 zoom-s2s.py list_meetings service@uperform.cn 5 upcoming\n\n# 创建会议 (start_time 格式: YYYY-MM-DDTHH:MM:SS)\npython3 zoom-s2s.py create_meeting \"煎饼果子讨论会\" \"2026-05-05T10:00:00\" 60 Asia/Shanghai\n\n# 获取云录像\npython3 zoom-s2s.py recordings service@uperform.cn 10\n```\n\n## 目录结构\n\n```\nzoom-s2s-oauth/\n├── SKILL.md           # AI Agent 调用说明\n├── README.md          # 本文件\n├── .env               # 凭证配置 (不要提交到 git!)\n└── scripts/\n    └── zoom-s2s.py    # 主脚本 (纯 Python3，无外部依赖)\n```\n\n\n## 对比：MCP vs Server-to-Server REST\n\n| | MCP 方式 | Server-to-Server REST |\n|---|---|---|\n| 需要 VPS | ✅ 需要 (OAuth 回调) | ❌ 不需要 |\n| 协议 | MCP (JSON-RPC) | 标准 REST (Python 无外部依赖) |\n| Token | User-Managed OAuth | Server-to-Server OAuth |\n| 复杂度 | 高 (代理+OAuth) | 低 (直接调) |\n| 功能 | Zoom MCP 工具集 | 7 个白名单 CLI action（list/get/create/delete meeting、get/list user、list recordings） |\n\n如果你只需要调用 Zoom 会议/录像等核心功能，Server-to-Server REST 方式更简单。"},{"path":"skill-card.md","content":"## Description:\n\nHelps agents manage Zoom meetings and look up account users and cloud recordings through seven approved Server-to-Server OAuth actions.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[mebusw](https://clawhub.ai/user/mebusw)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nZoom account administrators and their agents use this skill to schedule, find, and cancel meetings, retrieve cloud recording information, and look up account users.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Account-level credentials and cached access tokens could expose meeting and recording data.\n\nMitigation: Use a dedicated Zoom app, keep .env and token files private and out of repositories and sync tools, and avoid shared machines.\n\nRisk: Unnecessary Zoom permissions could enable deletion or access to sensitive recordings.\n\nMitigation: Grant only the required OAuth scopes; leave deletion and recording access disabled unless needed.\n\nRisk: Meeting deletion is irreversible and meeting host links are sensitive.\n\nMitigation: Require explicit confirmation before creating or deleting meetings, use --yes only after confirming deletion, and share attendee links rather than host links.\n\n## Reference(s):\n\n- [Source repository](https://github.com/mebusw/zoom-meeting-admin)\n- [ClawHub skill release](https://clawhub.ai/mebusw/skills/zoom-meeting-admin)\n- [Zoom App Marketplace](https://marketplace.zoom.us/)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Shell commands, Guidance]\n\n**Output Format:** [Markdown with meeting details and links]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May include meeting IDs, attendee links, user details, and recording information; never disclose credentials or host links.]\n\n## Skill Version(s):\n\n1.0.6 (source: ClawHub release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":1843,"uniquenessScore":36,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-10T09:47:59.817Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-10T09:47:59.817Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T11:52:50.409Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}