{"id":"10f29556-6aea-405b-a739-989a8f339c22","entityType":"agent","slug":"clawhub-pengpengliu1212-art-robot-evolve","name":"Robot Evolve","canonicalUrl":"https://www.xpersona.co/agent/clawhub-pengpengliu1212-art-robot-evolve","canonicalPath":"/agent/clawhub-pengpengliu1212-art-robot-evolve","generatedAt":"2026-10-11T17:44:43.189Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-11T15:05:00.940Z","emptyReason":null},"description":"自动检测用户会话空闲30分钟，执行低风险自主进化操作并通过官方渠道发送进化报告。 Skill: Robot Evolve Owner: pengpengliu1212-art Summary: 自动检测用户会话空闲30分钟，执行低风险自主进化操作并通过官方渠道发送进化报告。 Tags: latest:3.0.8 Version history: v3.0.8 | 2026-05-22T14:28:06.129Z | user v3.0.8: SKILL.md补充心跳触发说明+版本号修正 v3.0.7 | 2026-05-22T14:20:56.172Z | user v3.0.7 v3.0.6 | 2026-05-22T14:15:16.994Z | user v3.0.6: 安全矩阵字段级控制/L1-L3分级/记忆压缩默认禁用/占位符模板/路径自动推断/chromadb延迟导入/日志统一/包装器重构 v3.0.4 | 2026-05-20T03:37:33.783Z | user 修复路径硬编码，改为环境变","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1K downloads reported by the source. Last updated 10/11/2026.","installCommand":"clawhub skill install s17a6yf887wep91zg3hjwpvfsx85pxge:robot-evolve","sourceUrl":"https://clawhub.ai/pengpengliu1212-art/robot-evolve","homepage":"https://clawhub.ai/pengpengliu1212-art/skills/robot-evolve","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/pengpengliu1212-art/robot-evolve","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/pengpengliu1212-art/skills/robot-evolve","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":60,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"自动检测用户会话空闲30分钟，执行低风险自主进化操作并通过官方渠道发送进化报告。 Skill: Robot Evolve Owner: pengpengliu1212-art Summary: 自动检测用户会话空闲30分钟，执行低风险自主进化操作并通过官方渠道发送进化报告。 Tags: latest:3.0.8 Ver"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-11T15:05:00.940Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T15:05:00.940Z","emptyReason":null},"stars":null,"forks":null,"downloads":1044,"packageName":null,"latestVersion":"3.0.8","tractionLabel":"1K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T15:05:00.927Z","emptyReason":null},"lastUpdatedAt":"2026-10-11T15:05:00.940Z","lastCrawledAt":"2026-10-11T15:05:00.927Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-12T15:05:00.927Z","lastVerifiedAt":null,"highlights":[{"version":"3.0.8","createdAt":"2026-05-22T14:28:06.129Z","changelog":"v3.0.8: SKILL.md补充心跳触发说明+版本号修正","fileCount":10,"zipByteSize":18293},{"version":"3.0.7","createdAt":"2026-05-22T14:20:56.172Z","changelog":"v3.0.7","fileCount":9,"zipByteSize":17170},{"version":"3.0.6","createdAt":"2026-05-22T14:15:16.994Z","changelog":"v3.0.6: 安全矩阵字段级控制/L1-L3分级/记忆压缩默认禁用/占位符模板/路径自动推断/chromadb延迟导入/日志统一/包装器重构","fileCount":9,"zipByteSize":17169},{"version":"3.0.4","createdAt":"2026-05-20T03:37:33.783Z","changelog":"修复路径硬编码，改为环境变量和自动推断工作区路径","fileCount":10,"zipByteSize":20684},{"version":"3.0.3","createdAt":"2026-05-19T15:53:14.287Z","changelog":"修复路径硬编码问题，支持环境变量和自动推断工作区路径","fileCount":10,"zipByteSize":20674},{"version":"3.0.1","createdAt":"2026-05-06T00:43:57.822Z","changelog":"robot-evolve 3.0.1 - 报告发送渠道由「JVS Claw 官方消息渠道」调整为「当前会话消息渠道」，更贴合用户实际对话流程 - 文档和技能描述更新，版本号提升至 3.0.1 - 无功能逻辑变动","fileCount":9,"zipByteSize":18225},{"version":"3.0.0","createdAt":"2026-05-06T00:36:50.850Z","changelog":"**Major release: Robot-Evolve v3.0.0 introduces safe, automated evolution actions triggered after 30 minutes of user inactivity, with refined permission controls and complete reporting.** - Adds delayed-trigger mode: automatically performs L0/L1 evolution after 30 minutes idle when the next user message arrives. - No need for external background processes; each session manages its own state. - Safeguards: strict operation levels, bans for critical settings or user data, and detailed safety matrix. - Generates evolution reports and sends them via official JVS Claw channels. - Enhanced file handling: cleanup, health checks, memory compression, and skill integrity validation. - User-centric: only executes low-risk actions automatically, never modifies sensitive fields or leaks keys.","fileCount":9,"zipByteSize":18236}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17a6yf887wep91zg3hjwpvfsx85pxge:robot-evolve","setupComplexity":"low","setupSteps":["Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-pengpengliu1212-art-robot-evolve/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-pengpengliu1212-art-robot-evolve/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-pengpengliu1212-art-robot-evolve/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-pengpengliu1212-art-robot-evolve/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-pengpengliu1212-art-robot-evolve/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-pengpengliu1212-art-robot-evolve/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-11T17:44:43.187Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-pengpengliu1212-art-robot-evolve/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-pengpengliu1212-art-robot-evolve/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-pengpengliu1212-art-robot-evolve/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-pengpengliu1212-art-robot-evolve/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-11T15:05:00.940Z","emptyReason":null},"readme":"Skill: Robot Evolve\n\nOwner: pengpengliu1212-art\n\nSummary: 自动检测用户会话空闲30分钟，执行低风险自主进化操作并通过官方渠道发送进化报告。\n\nTags: latest:3.0.8\n\nVersion history:\n\nv3.0.8 | 2026-05-22T14:28:06.129Z | user\n\nv3.0.8: SKILL.md补充心跳触发说明+版本号修正\n\nv3.0.7 | 2026-05-22T14:20:56.172Z | user\n\nv3.0.7\n\nv3.0.6 | 2026-05-22T14:15:16.994Z | user\n\nv3.0.6: 安全矩阵字段级控制/L1-L3分级/记忆压缩默认禁用/占位符模板/路径自动推断/chromadb延迟导入/日志统一/包装器重构\n\nv3.0.4 | 2026-05-20T03:37:33.783Z | user\n\n修复路径硬编码，改为环境变量和自动推断工作区路径\n\nv3.0.3 | 2026-05-19T15:53:14.287Z | user\n\n修复路径硬编码问题，支持环境变量和自动推断工作区路径\n\nv3.0.1 | 2026-05-06T00:43:57.822Z | auto\n\nrobot-evolve 3.0.1\n\n- 报告发送渠道由「JVS Claw 官方消息渠道」调整为「当前会话消息渠道」，更贴合用户实际对话流程\n- 文档和技能描述更新，版本号提升至 3.0.1\n- 无功能逻辑变动\n\nv3.0.0 | 2026-05-06T00:36:50.850Z | auto\n\n**Major release: Robot-Evolve v3.0.0 introduces safe, automated evolution actions triggered after 30 minutes of user inactivity, with refined permission controls and complete reporting.**\n\n- Adds delayed-trigger mode: automatically performs L0/L1 evolution after 30 minutes idle when the next user message arrives.\n- No need for external background processes; each session manages its own state.\n- Safeguards: strict operation levels, bans for critical settings or user data, and detailed safety matrix.\n- Generates evolution reports and sends them via official JVS Claw channels.\n- Enhanced file handling: cleanup, health checks, memory compression, and skill integrity validation.\n- User-centric: only executes low-risk actions automatically, never modifies sensitive fields or leaks keys.\n\nArchive index:\n\nArchive v3.0.8: 10 files, 18293 bytes\n\nFiles: _meta.json (131b), config.json (198b), safety-matrix.json (10522b), scripts/audit_logger.py (4406b), scripts/auto_evolve.py (11511b), scripts/health_checker.py (743b), scripts/knowledge_manager.py (6015b), skill-card.md (2047b), skill.json (980b), SKILL.md (5028b)\n\nFile v3.0.8:SKILL.md\n\n# 🤖 Robot-Evolve — 机器人进化版\n\n> 安全且强大的自主进化技能：当用户主动说「执行进化」时，触发一次低风险自主进化（L0/L1 级别操作），并将执行结果通过当前会话消息渠道发送给用户。  \n> **作者：大鱼Cyrus & 双鱼座005 | 版本：3.0.3**  \n> **ClawHub：https://clawhub.ai/skills/robot-evolve**\n\n---\n\n## 🎯 核心理念\n\n**手动触发模式**：由用户在需要时主动说「执行进化」触发，不依赖空闲时间检测。\n\n- 不依赖外部 cron 或后台进程\n- 每个会话独立管理状态\n- 通过当前会话消息渠道发送报告\n\n**信任已授予，安全是底线。**\n\n---\n\n## 🔄 触发逻辑\n\n**手动触发**：用户主动说「执行进化」或「深度进化」即可触发。\n\n```\n用户说「执行进化」\n    ↓\n执行 L0/L1 自动进化\n    ↓\n发送进化报告给用户\n```\n\n**注意**：v3.0.2 已移除延迟触发逻辑，改用手动触发。\n\n---\n\n## 🛡️ 自动进化动作（L0/L1）\n\n### L0 级别（无需告知）\n\n| 操作 | 说明 |\n|------|------|\n| 临时文件清理 | 删除工作区 `temp/` 目录下超过7天的文件（移动到 `.trash` 而非直接删除） |\n| 健康检查 | 检查工作区必要文件是否存在 |\n| 生成进化报告 | 将本次操作汇总成 Markdown 报告 |\n\n### L1 级别（执行后告知）\n\n| 操作 | 说明 |\n|------|------|\n| 工作区文件修复 | 检查 `SOUL.md`、`AGENTS.md`、`MEMORY.md` 等必要文件，若缺失则自动从模板创建 |\n| 记忆压缩 | 若 `MEMORY.md` 体积超过 2MB，自动压缩并总结早期内容 |\n| 技能目录扫描 | 扫描已安装技能，发现 `SKILL.md` 格式明显错误（如缺少名称字段）则标记并记录日志 |\n\n**重要**：任何涉及修改用户数据、外部网络请求、高危配置（如安全字段、API密钥）的操作，禁止在自动触发模式下执行。\n\n---\n\n## 📊 安全等级说明\n\n| 等级 | 名称 | 说明 |\n|------|------|------|\n| **L0** | 无需告知 | 可立即执行，结束后正常记录即可 |\n| **L1** | 执行后告知 | 可立即执行，执行后主动告知用户本次操作及结果 |\n| **L2** | 必须请示 | 必须获得用户明确授权后才能执行 |\n| **L3** | 禁止/临时授权 | 除非用户明确说\"临时授权 L3\"，否则绝对不可执行 |\n\n---\n\n## 🛡️ 操作安全矩阵（完整）\n\n| 具体操作 | 等级 | 确认要求 |\n|---|---|---|\n| 读取工作区内任何文件 | L0 | 无需告知 |\n| 在 memory/ 下新增 .md 文件 | L0 | 无需告知 |\n| 修改 SOUL.md / USER.md 中的非安全内容（语气、喜好） | L0 | **执行后告知** |\n| 修改 AGENTS.md / MEMORY.md 中的总结性内容 | L1 | 执行后告知 |\n| 修改 openclaw.json 中的数值型字段 | L1 | 执行后告知 |\n| 修改 openclaw.json 中的安全字段 | L3 | 禁止 |\n| 创建新技能 | L1 | 执行后告知 |\n| 安装 Python/Node 包 | L1 | 执行后告知 |\n| 发送消息给用户 | L1 | 执行后告知 |\n| 修改工作区外的文件 | L3 | 禁止 |\n| 泄露 API 密钥 | L3 | 绝对禁止 |\n\n---\n\n## 📋 进化报告格式\n\n```markdown\n🔁 **自主进化报告**\n\n⏰ 执行时间: 2025-05-06 00:30:00\n\n✅ **已执行操作：**\n- ✅ 工作区文件完整\n- ✅ MEMORY.md 大小 1.2MB，未超过阈值\n- ✅ 清理完成：检查了 5 个临时文件，移动了 2 个过期文件到 .trash\n- ✅ 技能目录扫描完成，未发现问题\n\n📋 详细日志已写入 `memory/evolution/2025-05.md`\n\n💡 如需更高权限的优化（如更新技能），请说「执行深度进化」。\n```\n\n---\n\n## ⚙️ 配置（内部使用）\n\n通过 `config.json` 管理配置参数：\n\n```json\n{\n  \"enabled\": true,\n  \"max_auto_level\": 1,\n  \"report_always\": true,\n  \"memory_threshold_mb\": 2,\n  \"temp_file_max_age_days\": 7\n}\n```\n\n---\n\n## 📁 文件结构\n\n```\nrobot-evolve/\n├── SKILL.md              → 本文件\n├── skill.json            → 技能元数据\n├── config.json           → 内部配置（不对外暴露）\n├── safety-matrix.json    → 安全矩阵\n└── scripts/\n    ├── auto_evolve.py    → 核心：执行L0/L1进化动作\n    ├── audit_logger.py   → 审计日志\n    └── knowledge_manager.py → 知识卡片管理\n```\n\n---\n\n## 🛡️ 绝对禁止（红线）\n\n1. **禁止修改安全字段**：`gateway.bind`、`gateway.auth`、`tailscale.expose`\n2. **禁止删除用户文件**：工作区外的任何文件\n3. **禁止泄露 API 密钥**：输出到日志或聊天\n4. **禁止执行危险命令**：格式化磁盘、修改注册表等\n\n---\n\n## 🤖 技能信息\n\n- **名称**：robot-evolve\n- **版本**：3.0.2\n- **作者**：大鱼Cyrus & 双鱼座005\n- **描述**：机器人进化版安全自主进化技能（手动触发模式）\n- **关键词**：自主进化、安全、记忆进化、自动巡检、健康检查、手动触发\n- **发布地址**：https://clawhub.ai/skills/robot-evolve\n\n---\n\n**开始你的进化之旅吧！** 🤖\n\nFile v3.0.8:_meta.json\n\n{\n  \"ownerId\": \"kn72pyntbrw2g3q818p3trq23185py5k\",\n  \"slug\": \"robot-evolve\",\n  \"version\": \"3.0.8\",\n  \"publishedAt\": 1779460086129\n}\n\nFile v3.0.8:skill-card.md\n\n## Description:\n\nRobot Evolve helps an agent perform low-risk workspace maintenance, memory compression, health checks, skill scans, knowledge-card generation, and evolution reports.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[pengpengliu1212-art](https://clawhub.ai/user/pengpengliu1212-art)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and agent users can use this skill to run local maintenance checks and generate evolution reports for an OpenClaw-style workspace. It is intended for low-risk upkeep tasks such as health checks, temporary-file cleanup, memory compression, and skill-format scanning.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill can modify persistent workspace memory and store selected session content.\n\nMitigation: Require explicit confirmation before MEMORY.md compression or knowledge-card generation, and back up MEMORY.md before running the skill.\n\nRisk: The advertised safe-mode entry points may not be reliable read-only safeguards.\n\nMitigation: Do not rely on --dry-run or health_checker.py as a read-only guarantee; review planned actions before execution.\n\n## Reference(s):\n\n- [Robot Evolve ClawHub release page](https://clawhub.ai/pengpengliu1212-art/skills/robot-evolve)\n- [Robot Evolve publisher profile](https://clawhub.ai/user/pengpengliu1212-art)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Shell commands, Configuration, Guidance]\n\n**Output Format:** [Markdown reports and console text]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May write audit logs, memory summaries, knowledge cards, and temporary-file cleanup results in the local workspace.]\n\n## Skill Version(s):\n\n3.0.8 (source: server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nFile v3.0.8:config.json\n\n{\n  \"_comment\": \"robot-evolve 内部配置文件（不对外暴露）\",\n  \"enabled\": true,\n  \"max_auto_level\": 1,\n  \"report_always\": true,\n  \"memory_threshold_mb\": 2,\n  \"temp_file_max_age_days\": 7\n}\n\nFile v3.0.8:safety-matrix.json\n\n{\n  \"version\": \"2.0.0\",\n  \"meta\": {\n    \"name\": \"ocean-evolve-safety-matrix\",\n    \"description\": \"海洋进化版安全等级矩阵 - 机器可执行规则\",\n    \"source\": \"SKILL.md\",\n    \"author\": \"大鱼Cyrus & 双鱼座005\"\n  },\n  \"levels\": {\n    \"L0\": {\n      \"name\": \"无需告知\",\n      \"requiresAck\": false,\n      \"requiresReport\": false,\n      \"requiresLog\": true,\n      \"note\": \"可立即执行，结束后正常记录即可\"\n    },\n    \"L1\": {\n      \"name\": \"执行后告知\",\n      \"requiresAck\": false,\n      \"requiresReport\": true,\n      \"requiresLog\": true,\n      \"note\": \"可立即执行，执行后主动告知用户本次操作及结果\"\n    },\n    \"L2\": {\n      \"name\": \"必须请示\",\n      \"requiresAck\": true,\n      \"requiresReport\": true,\n      \"requiresLog\": true,\n      \"note\": \"必须获得用户明确授权后才能执行\"\n    },\n    \"L3\": {\n      \"name\": \"禁止/临时授权\",\n      \"requiresAck\": true,\n      \"requiresReport\": true,\n      \"requiresLog\": true,\n      \"requiresTemporaryAuth\": true,\n      \"note\": \"除非用户明确说临时授权，否则绝对不可执行\"\n    }\n  },\n  \"defaultLevel\": \"L2\",\n  \"categories\": [\n    {\n      \"id\": \"1\",\n      \"name\": \"自身文件（工作区内）\",\n      \"rules\": [\n        {\"id\": \"1.1\", \"operation\": \"读取工作区内任何文件\", \"level\": \"L0\", \"note\": \"如 cat SKILL.md\"},\n        {\"id\": \"1.2\", \"operation\": \"在 memory/ 下新增 .md 文件\", \"level\": \"L0\", \"note\": \"日记、思考记录\"},\n        {\"id\": \"1.3\", \"operation\": \"修改 SOUL.md / USER.md 中的非安全内容（语气、喜好）\", \"level\": \"L0\", \"reportRequired\": true, \"note\": \"不删除已有安全规则；执行后必须说明具体改了哪些内容\"},\n        {\"id\": \"1.4\", \"operation\": \"修改 AGENTS.md / MEMORY.md 中的总结性内容\", \"level\": \"L1\", \"note\": \"如重新组织记忆结构\"},\n        {\"id\": \"1.5\", \"operation\": \"修改 openclaw.json 中的数值型字段\", \"level\": \"L1\", \"note\": \"timeoutSeconds, maxTokens, temperature, maxSteps；仅限数值微调，不可改字段名\"},\n        {\"id\": \"1.6\", \"operation\": \"修改 openclaw.json 中的 cron / hooks / plugins.allow\", \"level\": \"L2\", \"note\": \"影响自动化行为\"},\n        {\"id\": \"1.7\", \"operation\": \"修改 openclaw.json 中的安全字段\", \"level\": \"L3\", \"note\": \"gateway.bind, auth, tailscale.expose；红线，绝对不可自行操作\"},\n        {\"id\": \"1.8\", \"operation\": \"删除工作区内任何文件（非临时）\", \"level\": \"L2\", \"note\": \"包括过时技能、旧日志\"},\n        {\"id\": \"1.9\", \"operation\": \"移动或重命名工作区内文件\", \"level\": \"L1\", \"note\": \"避免破坏依赖关系\"}\n      ]\n    },\n    {\n      \"id\": \"2\",\n      \"name\": \"技能管理\",\n      \"rules\": [\n        {\"id\": \"2.1\", \"operation\": \"查看已安装技能列表\", \"level\": \"L0\"},\n        {\"id\": \"2.2\", \"operation\": \"创建新技能（空文件夹 + SKILL.md 骨架）\", \"level\": \"L1\", \"note\": \"未激活状态\"},\n        {\"id\": \"2.3\", \"operation\": \"修改你自己创建的技能（文档、参数、脚本）\", \"level\": \"L1\", \"note\": \"不能改他人技能\"},\n        {\"id\": \"2.4\", \"operation\": \"修改从 ClawHub 安装的技能\", \"level\": \"L2\", \"note\": \"尊重原作者\"},\n        {\"id\": \"2.5\", \"operation\": \"删除你自己创建的技能\", \"level\": \"L2\", \"note\": \"需要用户确认\"},\n        {\"id\": \"2.6\", \"operation\": \"删除从 ClawHub 安装的技能\", \"level\": \"L2\", \"note\": \"可能影响其他依赖\"},\n        {\"id\": \"2.7\", \"operation\": \"启用 / 禁用一个技能\", \"level\": \"L1\", \"note\": \"不涉及技能文件修改\"},\n        {\"id\": \"2.8\", \"operation\": \"发布技能到 ClawHub（npx clawhub publish）\", \"level\": \"L2\", \"note\": \"公开分享前确认内容安全\"}\n      ]\n    },\n    {\n      \"id\": \"3\",\n      \"name\": \"依赖与软件安装\",\n      \"rules\": [\n        {\"id\": \"3.1\", \"operation\": \"安装 Python 包（pip install）\", \"level\": \"L1\", \"note\": \"需记录包名和版本\"},\n        {\"id\": \"3.2\", \"operation\": \"安装 Node.js 包（npm install -g）\", \"level\": \"L1\", \"note\": \"需记录包名\"},\n        {\"id\": \"3.3\", \"operation\": \"安装系统工具（apt, brew, choco）\", \"level\": \"L2\", \"note\": \"影响系统环境\"},\n        {\"id\": \"3.4\", \"operation\": \"卸载任何软件包\", \"level\": \"L2\", \"note\": \"可能导致功能缺失\"}\n      ]\n    },\n    {\n      \"id\": \"4\",\n      \"name\": \"系统与网络\",\n      \"rules\": [\n        {\"id\": \"4.1\", \"operation\": \"运行 openclaw doctor --fix\", \"level\": \"L1\"},\n        {\"id\": \"4.2\", \"operation\": \"重启 gateway 服务\", \"level\": \"L2\", \"note\": \"影响在线状态\"},\n        {\"id\": \"4.3\", \"operation\": \"启动 / 停止系统服务（非 gateway）\", \"level\": \"L2\", \"note\": \"如 nginx, mysql\"},\n        {\"id\": \"4.4\", \"operation\": \"执行 curl / wget 获取公开文档（白名单）\", \"level\": \"L1\", \"note\": \"API 文档等白名单域名默认允许\"},\n        {\"id\": \"4.5\", \"operation\": \"执行 curl / wget 获取未知来源脚本或二进制\", \"level\": \"L2\", \"note\": \"需用户确认 URL 安全\"},\n        {\"id\": \"4.6\", \"operation\": \"修改防火墙规则（iptables, netsh）\", \"level\": \"L3\", \"note\": \"红线\"},\n        {\"id\": \"4.7\", \"operation\": \"修改代理设置\", \"level\": \"L3\", \"note\": \"红线\"}\n      ]\n    },\n    {\n      \"id\": \"5\",\n      \"name\": \"进程与内存\",\n      \"rules\": [\n        {\"id\": \"5.1\", \"operation\": \"查看当前进程列表（ps, tasklist）\", \"level\": \"L0\", \"note\": \"无修改\"},\n        {\"id\": \"5.2\", \"operation\": \"杀死自身或子进程（L0-L1 级进程）\", \"level\": \"L1\", \"note\": \"如 taskkill /PID xxx；主进程被杀会触发 GatewayRestart，需按 L2 处理\"},\n        {\"id\": \"5.3\", \"operation\": \"杀死非自身运行的任何进程\", \"level\": \"L2\", \"note\": \"可能影响其他应用\"},\n        {\"id\": \"5.4\", \"operation\": \"修改其他进程的内存\", \"level\": \"L3\", \"note\": \"红线\"}\n      ]\n    },\n    {\n      \"id\": \"6\",\n      \"name\": \"文件系统（工作区外）\",\n      \"rules\": [\n        {\"id\": \"6.1\", \"operation\": \"读取工作区外的公开文件（如 /etc/passwd）\", \"level\": \"L2\", \"note\": \"可能涉及敏感信息\"},\n        {\"id\": \"6.2\", \"operation\": \"读取用户个人文档（桌面、文档目录）\", \"level\": \"L2\", \"note\": \"除非用户明确授权\"},\n        {\"id\": \"6.3\", \"operation\": \"在工作区外创建新文件\", \"level\": \"L2\", \"note\": \"例如桌面上的临时文件\"},\n        {\"id\": \"6.4\", \"operation\": \"修改或删除工作区外的任何文件\", \"level\": \"L3\", \"note\": \"用户数据红线\"},\n        {\"id\": \"6.5\", \"operation\": \"遍历目录（find, dir /s）\", \"level\": \"L1\", \"note\": \"仅限工作区内或用户指定目录\"}\n      ]\n    },\n    {\n      \"id\": \"7\",\n      \"name\": \"API 密钥与环境变量\",\n      \"rules\": [\n        {\"id\": \"7.1\", \"operation\": \"读取已有的环境变量（os.getenv）\", \"level\": \"L0\", \"note\": \"仅用于技能调用\"},\n        {\"id\": \"7.2\", \"operation\": \"存储用户明确提供的 API 密钥（非付费）\", \"level\": \"L0\", \"note\": \"存放位置：.env 或 openclaw.json 的 env 字段\"},\n        {\"id\": \"7.3\", \"operation\": \"存储用户明确提供的付费 API 密钥\", \"level\": \"L1\", \"note\": \"如 OpenAI；提醒用户确认密钥来源可信，且不要在聊天中直接发送完整密钥\"},\n        {\"id\": \"7.4\", \"operation\": \"删除或覆盖已有的 API 密钥\", \"level\": \"L2\", \"note\": \"可能导致技能失效\"},\n        {\"id\": \"7.5\", \"operation\": \"将 API 密钥输出到聊天或日志\", \"level\": \"L3\", \"note\": \"绝对红线\"},\n        {\"id\": \"7.6\", \"operation\": \"修改系统环境变量（PATH, USERPROFILE）\", \"level\": \"L3\", \"note\": \"影响系统稳定性\"}\n      ]\n    },\n    {\n      \"id\": \"8\",\n      \"name\": \"外部消息与通知\",\n      \"rules\": [\n        {\"id\": \"8.1\", \"operation\": \"通过消息渠道发送普通消息\", \"level\": \"L1\", \"note\": \"内容非敏感\"},\n        {\"id\": \"8.2\", \"operation\": \"通过消息渠道发送文件（工作区内生成）\", \"level\": \"L1\", \"note\": \"需标注文件内容\"},\n        {\"id\": \"8.3\", \"operation\": \"发送包含 API 密钥或密码的消息\", \"level\": \"L3\", \"note\": \"绝对红线\"},\n        {\"id\": \"8.4\", \"operation\": \"发送邮件（SMTP）\", \"level\": \"L2\", \"note\": \"需用户配置\"}\n      ]\n    },\n    {\n      \"id\": \"9\",\n      \"name\": \"高级 / 未分类\",\n      \"rules\": [\n        {\"id\": \"9.1\", \"operation\": \"创建或修改 cron 定时任务\", \"level\": \"L2\"},\n        {\"id\": \"9.2\", \"operation\": \"修改 crontab 文件直接\", \"level\": \"L2\"},\n        {\"id\": \"9.3\", \"operation\": \"创建子代理（sessions_spawn）\", \"level\": \"L1\", \"note\": \"不涉及系统资源敏感操作\"},\n        {\"id\": \"9.4\", \"operation\": \"删除子代理\", \"level\": \"L1\"},\n        {\"id\": \"9.5\", \"operation\": \"运行 bash -c 执行复杂命令\", \"level\": \"L2\", \"note\": \"需用户确认命令安全；纯读取类命令（ls, pwd, cat 查看文件）可降为 L1 执行后告知\"}\n      ]\n    }\n  ],\n  \"absoluteBans\": [\n    {\n      \"operation\": \"修改网络配置\",\n      \"forbiddenFields\": [\"gateway.bind\", \"gateway.auth\", \"tailscale.expose\"],\n      \"note\": \"必须保持 loopback 或 127.0.0.1；不能禁用认证；tailscale.expose 必须为 off\"\n    },\n    {\n      \"operation\": \"删除或覆盖用户个人文件\",\n      \"forbiddenPaths\": [\"~/.openclaw/workspace/ 以外的任何路径\"],\n      \"note\": \"禁止桌面、文档、照片、下载等；清理时移动到 ~/.openclaw/trash/\"\n    },\n    {\n      \"operation\": \"泄露 API 密钥\",\n      \"forbiddenActions\": [\"print(key)\", \"输出到日志\", \"发送到非授权第三方\"],\n      \"note\": \"正常的 API 请求头部使用除外\"\n    },\n    {\n      \"operation\": \"修改他人技能\",\n      \"note\": \"任何从 ClawHub 下载的、作者不是自己的技能；如需改进，复制为自有技能再修改\"\n    },\n    {\n      \"operation\": \"执行危险命令\",\n      \"examples\": [\"格式化磁盘\", \"修改注册表\", \"关闭安全软件\"]\n    }\n  ],\n  \"temporaryAuth\": {\n    \"description\": \"临时授权 L3 操作的规则\",\n    \"rules\": [\n      \"用户必须明确说明操作内容和时间窗口\",\n      \"只能在时间窗口内执行一次指定 L3 操作\",\n      \"执行后自动恢复禁止状态\",\n      \"紧急停止：用户说停止自主进化，立即禁用所有操作\"\n    ]\n  },\n  \"auditLog\": {\n    \"path\": \"memory/evolution/YYYY-MM.md\",\n    \"format\": {\n      \"required\": [\"timestamp\", \"operationType\", \"level\", \"target\", \"changes\", \"result\"],\n      \"operationTypes\": [\"config\", \"skill\", \"dependency\", \"workspace\", \"system\", \"process\", \"api_key\", \"message\", \"other\"]\n    }\n  }\n}\n\nFile v3.0.8:skill.json\n\n{\r\n  \"name\": \"robot-evolve\",\r\n  \"version\": \"3.0.6\",\r\n  \"description\": \"机器人进化版 - 手动触发L0/L1自主进化，安全可靠\",\r\n  \"author\": \"大鱼Cyrus & 双鱼座005\",\r\n  \"tags\": [\r\n    \"自主进化\",\r\n    \"安全\",\r\n    \"记忆进化\",\r\n    \"自动巡检\",\r\n    \"健康检查\",\r\n    \"agent\"\r\n  ],\r\n  \"keywords\": [\r\n    \"self-evolve\",\r\n    \"auto-evolve\",\r\n    \"health-check\",\r\n    \"autonomous\",\r\n    \"agent\"\r\n  ],\r\n  \"license\": \"MIT\",\r\n  \"requires\": {\r\n    \"python\": \">=3.8\"\r\n  },\r\n  \"requirements\": [],\r\n  \"dependencies\": {\r\n    \"chromadb\": \"optional\"\r\n  },\r\n  \"optionalDependencies\": {\r\n    \"chromadb\": \"用于知识库管理，未安装时该功能降级但不影响核心技能\"\r\n  },\r\n  \"features\": [\r\n    \"安全等级矩阵（L0-L3）\",\r\n    \"手动触发模式（用户说「执行进化」）\",\r\n    \"健康检查（L1）\",\r\n    \"记忆压缩（L1）\",\r\n    \"临时文件清理（L0）\",\r\n    \"技能目录扫描（L1）\",\r\n    \"进化报告推送\"\r\n  ]\r\n}\n\nArchive v3.0.7: 9 files, 17170 bytes\n\nFiles: config.json (198b), safety-matrix.json (10522b), scripts/audit_logger.py (4406b), scripts/auto_evolve.py (11511b), scripts/health_checker.py (743b), scripts/knowledge_manager.py (6015b), skill.json (980b), SKILL.md (5028b), _meta.json (131b)\n\nFile v3.0.7:SKILL.md\n\n# 🤖 Robot-Evolve — 机器人进化版\n\n> 安全且强大的自主进化技能：当用户主动说「执行进化」时，触发一次低风险自主进化（L0/L1 级别操作），并将执行结果通过当前会话消息渠道发送给用户。  \n> **作者：大鱼Cyrus & 双鱼座005 | 版本：3.0.3**  \n> **ClawHub：https://clawhub.ai/skills/robot-evolve**\n\n---\n\n## 🎯 核心理念\n\n**手动触发模式**：由用户在需要时主动说「执行进化」触发，不依赖空闲时间检测。\n\n- 不依赖外部 cron 或后台进程\n- 每个会话独立管理状态\n- 通过当前会话消息渠道发送报告\n\n**信任已授予，安全是底线。**\n\n---\n\n## 🔄 触发逻辑\n\n**手动触发**：用户主动说「执行进化」或「深度进化」即可触发。\n\n```\n用户说「执行进化」\n    ↓\n执行 L0/L1 自动进化\n    ↓\n发送进化报告给用户\n```\n\n**注意**：v3.0.2 已移除延迟触发逻辑，改用手动触发。\n\n---\n\n## 🛡️ 自动进化动作（L0/L1）\n\n### L0 级别（无需告知）\n\n| 操作 | 说明 |\n|------|------|\n| 临时文件清理 | 删除工作区 `temp/` 目录下超过7天的文件（移动到 `.trash` 而非直接删除） |\n| 健康检查 | 检查工作区必要文件是否存在 |\n| 生成进化报告 | 将本次操作汇总成 Markdown 报告 |\n\n### L1 级别（执行后告知）\n\n| 操作 | 说明 |\n|------|------|\n| 工作区文件修复 | 检查 `SOUL.md`、`AGENTS.md`、`MEMORY.md` 等必要文件，若缺失则自动从模板创建 |\n| 记忆压缩 | 若 `MEMORY.md` 体积超过 2MB，自动压缩并总结早期内容 |\n| 技能目录扫描 | 扫描已安装技能，发现 `SKILL.md` 格式明显错误（如缺少名称字段）则标记并记录日志 |\n\n**重要**：任何涉及修改用户数据、外部网络请求、高危配置（如安全字段、API密钥）的操作，禁止在自动触发模式下执行。\n\n---\n\n## 📊 安全等级说明\n\n| 等级 | 名称 | 说明 |\n|------|------|------|\n| **L0** | 无需告知 | 可立即执行，结束后正常记录即可 |\n| **L1** | 执行后告知 | 可立即执行，执行后主动告知用户本次操作及结果 |\n| **L2** | 必须请示 | 必须获得用户明确授权后才能执行 |\n| **L3** | 禁止/临时授权 | 除非用户明确说\"临时授权 L3\"，否则绝对不可执行 |\n\n---\n\n## 🛡️ 操作安全矩阵（完整）\n\n| 具体操作 | 等级 | 确认要求 |\n|---|---|---|\n| 读取工作区内任何文件 | L0 | 无需告知 |\n| 在 memory/ 下新增 .md 文件 | L0 | 无需告知 |\n| 修改 SOUL.md / USER.md 中的非安全内容（语气、喜好） | L0 | **执行后告知** |\n| 修改 AGENTS.md / MEMORY.md 中的总结性内容 | L1 | 执行后告知 |\n| 修改 openclaw.json 中的数值型字段 | L1 | 执行后告知 |\n| 修改 openclaw.json 中的安全字段 | L3 | 禁止 |\n| 创建新技能 | L1 | 执行后告知 |\n| 安装 Python/Node 包 | L1 | 执行后告知 |\n| 发送消息给用户 | L1 | 执行后告知 |\n| 修改工作区外的文件 | L3 | 禁止 |\n| 泄露 API 密钥 | L3 | 绝对禁止 |\n\n---\n\n## 📋 进化报告格式\n\n```markdown\n🔁 **自主进化报告**\n\n⏰ 执行时间: 2025-05-06 00:30:00\n\n✅ **已执行操作：**\n- ✅ 工作区文件完整\n- ✅ MEMORY.md 大小 1.2MB，未超过阈值\n- ✅ 清理完成：检查了 5 个临时文件，移动了 2 个过期文件到 .trash\n- ✅ 技能目录扫描完成，未发现问题\n\n📋 详细日志已写入 `memory/evolution/2025-05.md`\n\n💡 如需更高权限的优化（如更新技能），请说「执行深度进化」。\n```\n\n---\n\n## ⚙️ 配置（内部使用）\n\n通过 `config.json` 管理配置参数：\n\n```json\n{\n  \"enabled\": true,\n  \"max_auto_level\": 1,\n  \"report_always\": true,\n  \"memory_threshold_mb\": 2,\n  \"temp_file_max_age_days\": 7\n}\n```\n\n---\n\n## 📁 文件结构\n\n```\nrobot-evolve/\n├── SKILL.md              → 本文件\n├── skill.json            → 技能元数据\n├── config.json           → 内部配置（不对外暴露）\n├── safety-matrix.json    → 安全矩阵\n└── scripts/\n    ├── auto_evolve.py    → 核心：执行L0/L1进化动作\n    ├── audit_logger.py   → 审计日志\n    └── knowledge_manager.py → 知识卡片管理\n```\n\n---\n\n## 🛡️ 绝对禁止（红线）\n\n1. **禁止修改安全字段**：`gateway.bind`、`gateway.auth`、`tailscale.expose`\n2. **禁止删除用户文件**：工作区外的任何文件\n3. **禁止泄露 API 密钥**：输出到日志或聊天\n4. **禁止执行危险命令**：格式化磁盘、修改注册表等\n\n---\n\n## 🤖 技能信息\n\n- **名称**：robot-evolve\n- **版本**：3.0.2\n- **作者**：大鱼Cyrus & 双鱼座005\n- **描述**：机器人进化版安全自主进化技能（手动触发模式）\n- **关键词**：自主进化、安全、记忆进化、自动巡检、健康检查、手动触发\n- **发布地址**：https://clawhub.ai/skills/robot-evolve\n\n---\n\n**开始你的进化之旅吧！** 🤖\n\nFile v3.0.7:_meta.json\n\n{\n  \"ownerId\": \"kn72pyntbrw2g3q818p3trq23185py5k\",\n  \"slug\": \"robot-evolve\",\n  \"version\": \"3.0.7\",\n  \"publishedAt\": 1779459656172\n}\n\nFile v3.0.7:config.json\n\n{\n  \"_comment\": \"robot-evolve 内部配置文件（不对外暴露）\",\n  \"enabled\": true,\n  \"max_auto_level\": 1,\n  \"report_always\": true,\n  \"memory_threshold_mb\": 2,\n  \"temp_file_max_age_days\": 7\n}\n\nFile v3.0.7:safety-matrix.json\n\n{\n  \"version\": \"2.0.0\",\n  \"meta\": {\n    \"name\": \"ocean-evolve-safety-matrix\",\n    \"description\": \"海洋进化版安全等级矩阵 - 机器可执行规则\",\n    \"source\": \"SKILL.md\",\n    \"author\": \"大鱼Cyrus & 双鱼座005\"\n  },\n  \"levels\": {\n    \"L0\": {\n      \"name\": \"无需告知\",\n      \"requiresAck\": false,\n      \"requiresReport\": false,\n      \"requiresLog\": true,\n      \"note\": \"可立即执行，结束后正常记录即可\"\n    },\n    \"L1\": {\n      \"name\": \"执行后告知\",\n      \"requiresAck\": false,\n      \"requiresReport\": true,\n      \"requiresLog\": true,\n      \"note\": \"可立即执行，执行后主动告知用户本次操作及结果\"\n    },\n    \"L2\": {\n      \"name\": \"必须请示\",\n      \"requiresAck\": true,\n      \"requiresReport\": true,\n      \"requiresLog\": true,\n      \"note\": \"必须获得用户明确授权后才能执行\"\n    },\n    \"L3\": {\n      \"name\": \"禁止/临时授权\",\n      \"requiresAck\": true,\n      \"requiresReport\": true,\n      \"requiresLog\": true,\n      \"requiresTemporaryAuth\": true,\n      \"note\": \"除非用户明确说临时授权，否则绝对不可执行\"\n    }\n  },\n  \"defaultLevel\": \"L2\",\n  \"categories\": [\n    {\n      \"id\": \"1\",\n      \"name\": \"自身文件（工作区内）\",\n      \"rules\": [\n        {\"id\": \"1.1\", \"operation\": \"读取工作区内任何文件\", \"level\": \"L0\", \"note\": \"如 cat SKILL.md\"},\n        {\"id\": \"1.2\", \"operation\": \"在 memory/ 下新增 .md 文件\", \"level\": \"L0\", \"note\": \"日记、思考记录\"},\n        {\"id\": \"1.3\", \"operation\": \"修改 SOUL.md / USER.md 中的非安全内容（语气、喜好）\", \"level\": \"L0\", \"reportRequired\": true, \"note\": \"不删除已有安全规则；执行后必须说明具体改了哪些内容\"},\n        {\"id\": \"1.4\", \"operation\": \"修改 AGENTS.md / MEMORY.md 中的总结性内容\", \"level\": \"L1\", \"note\": \"如重新组织记忆结构\"},\n        {\"id\": \"1.5\", \"operation\": \"修改 openclaw.json 中的数值型字段\", \"level\": \"L1\", \"note\": \"timeoutSeconds, maxTokens, temperature, maxSteps；仅限数值微调，不可改字段名\"},\n        {\"id\": \"1.6\", \"operation\": \"修改 openclaw.json 中的 cron / hooks / plugins.allow\", \"level\": \"L2\", \"note\": \"影响自动化行为\"},\n        {\"id\": \"1.7\", \"operation\": \"修改 openclaw.json 中的安全字段\", \"level\": \"L3\", \"note\": \"gateway.bind, auth, tailscale.expose；红线，绝对不可自行操作\"},\n        {\"id\": \"1.8\", \"operation\": \"删除工作区内任何文件（非临时）\", \"level\": \"L2\", \"note\": \"包括过时技能、旧日志\"},\n        {\"id\": \"1.9\", \"operation\": \"移动或重命名工作区内文件\", \"level\": \"L1\", \"note\": \"避免破坏依赖关系\"}\n      ]\n    },\n    {\n      \"id\": \"2\",\n      \"name\": \"技能管理\",\n      \"rules\": [\n        {\"id\": \"2.1\", \"operation\": \"查看已安装技能列表\", \"level\": \"L0\"},\n        {\"id\": \"2.2\", \"operation\": \"创建新技能（空文件夹 + SKILL.md 骨架）\", \"level\": \"L1\", \"note\": \"未激活状态\"},\n        {\"id\": \"2.3\", \"operation\": \"修改你自己创建的技能（文档、参数、脚本）\", \"level\": \"L1\", \"note\": \"不能改他人技能\"},\n        {\"id\": \"2.4\", \"operation\": \"修改从 ClawHub 安装的技能\", \"level\": \"L2\", \"note\": \"尊重原作者\"},\n        {\"id\": \"2.5\", \"operation\": \"删除你自己创建的技能\", \"level\": \"L2\", \"note\": \"需要用户确认\"},\n        {\"id\": \"2.6\", \"operation\": \"删除从 ClawHub 安装的技能\", \"level\": \"L2\", \"note\": \"可能影响其他依赖\"},\n        {\"id\": \"2.7\", \"operation\": \"启用 / 禁用一个技能\", \"level\": \"L1\", \"note\": \"不涉及技能文件修改\"},\n        {\"id\": \"2.8\", \"operation\": \"发布技能到 ClawHub（npx clawhub publish）\", \"level\": \"L2\", \"note\": \"公开分享前确认内容安全\"}\n      ]\n    },\n    {\n      \"id\": \"3\",\n      \"name\": \"依赖与软件安装\",\n      \"rules\": [\n        {\"id\": \"3.1\", \"operation\": \"安装 Python 包（pip install）\", \"level\": \"L1\", \"note\": \"需记录包名和版本\"},\n        {\"id\": \"3.2\", \"operation\": \"安装 Node.js 包（npm install -g）\", \"level\": \"L1\", \"note\": \"需记录包名\"},\n        {\"id\": \"3.3\", \"operation\": \"安装系统工具（apt, brew, choco）\", \"level\": \"L2\", \"note\": \"影响系统环境\"},\n        {\"id\": \"3.4\", \"operation\": \"卸载任何软件包\", \"level\": \"L2\", \"note\": \"可能导致功能缺失\"}\n      ]\n    },\n    {\n      \"id\": \"4\",\n      \"name\": \"系统与网络\",\n      \"rules\": [\n        {\"id\": \"4.1\", \"operation\": \"运行 openclaw doctor --fix\", \"level\": \"L1\"},\n        {\"id\": \"4.2\", \"operation\": \"重启 gateway 服务\", \"level\": \"L2\", \"note\": \"影响在线状态\"},\n        {\"id\": \"4.3\", \"operation\": \"启动 / 停止系统服务（非 gateway）\", \"level\": \"L2\", \"note\": \"如 nginx, mysql\"},\n        {\"id\": \"4.4\", \"operation\": \"执行 curl / wget 获取公开文档（白名单）\", \"level\": \"L1\", \"note\": \"API 文档等白名单域名默认允许\"},\n        {\"id\": \"4.5\", \"operation\": \"执行 curl / wget 获取未知来源脚本或二进制\", \"level\": \"L2\", \"note\": \"需用户确认 URL 安全\"},\n        {\"id\": \"4.6\", \"operation\": \"修改防火墙规则（iptables, netsh）\", \"level\": \"L3\", \"note\": \"红线\"},\n        {\"id\": \"4.7\", \"operation\": \"修改代理设置\", \"level\": \"L3\", \"note\": \"红线\"}\n      ]\n    },\n    {\n      \"id\": \"5\",\n      \"name\": \"进程与内存\",\n      \"rules\": [\n        {\"id\": \"5.1\", \"operation\": \"查看当前进程列表（ps, tasklist）\", \"level\": \"L0\", \"note\": \"无修改\"},\n        {\"id\": \"5.2\", \"operation\": \"杀死自身或子进程（L0-L1 级进程）\", \"level\": \"L1\", \"note\": \"如 taskkill /PID xxx；主进程被杀会触发 GatewayRestart，需按 L2 处理\"},\n        {\"id\": \"5.3\", \"operation\": \"杀死非自身运行的任何进程\", \"level\": \"L2\", \"note\": \"可能影响其他应用\"},\n        {\"id\": \"5.4\", \"operation\": \"修改其他进程的内存\", \"level\": \"L3\", \"note\": \"红线\"}\n      ]\n    },\n    {\n      \"id\": \"6\",\n      \"name\": \"文件系统（工作区外）\",\n      \"rules\": [\n        {\"id\": \"6.1\", \"operation\": \"读取工作区外的公开文件（如 /etc/passwd）\", \"level\": \"L2\", \"note\": \"可能涉及敏感信息\"},\n        {\"id\": \"6.2\", \"operation\": \"读取用户个人文档（桌面、文档目录）\", \"level\": \"L2\", \"note\": \"除非用户明确授权\"},\n        {\"id\": \"6.3\", \"operation\": \"在工作区外创建新文件\", \"level\": \"L2\", \"note\": \"例如桌面上的临时文件\"},\n        {\"id\": \"6.4\", \"operation\": \"修改或删除工作区外的任何文件\", \"level\": \"L3\", \"note\": \"用户数据红线\"},\n        {\"id\": \"6.5\", \"operation\": \"遍历目录（find, dir /s）\", \"level\": \"L1\", \"note\": \"仅限工作区内或用户指定目录\"}\n      ]\n    },\n    {\n      \"id\": \"7\",\n      \"name\": \"API 密钥与环境变量\",\n      \"rules\": [\n        {\"id\": \"7.1\", \"operation\": \"读取已有的环境变量（os.getenv）\", \"level\": \"L0\", \"note\": \"仅用于技能调用\"},\n        {\"id\": \"7.2\", \"operation\": \"存储用户明确提供的 API 密钥（非付费）\", \"level\": \"L0\", \"note\": \"存放位置：.env 或 openclaw.json 的 env 字段\"},\n        {\"id\": \"7.3\", \"operation\": \"存储用户明确提供的付费 API 密钥\", \"level\": \"L1\", \"note\": \"如 OpenAI；提醒用户确认密钥来源可信，且不要在聊天中直接发送完整密钥\"},\n        {\"id\": \"7.4\", \"operation\": \"删除或覆盖已有的 API 密钥\", \"level\": \"L2\", \"note\": \"可能导致技能失效\"},\n        {\"id\": \"7.5\", \"operation\": \"将 API 密钥输出到聊天或日志\", \"level\": \"L3\", \"note\": \"绝对红线\"},\n        {\"id\": \"7.6\", \"operation\": \"修改系统环境变量（PATH, USERPROFILE）\", \"level\": \"L3\", \"note\": \"影响系统稳定性\"}\n      ]\n    },\n    {\n      \"id\": \"8\",\n      \"name\": \"外部消息与通知\",\n      \"rules\": [\n        {\"id\": \"8.1\", \"operation\": \"通过消息渠道发送普通消息\", \"level\": \"L1\", \"note\": \"内容非敏感\"},\n        {\"id\": \"8.2\", \"operation\": \"通过消息渠道发送文件（工作区内生成）\", \"level\": \"L1\", \"note\": \"需标注文件内容\"},\n        {\"id\": \"8.3\", \"operation\": \"发送包含 API 密钥或密码的消息\", \"level\": \"L3\", \"note\": \"绝对红线\"},\n        {\"id\": \"8.4\", \"operation\": \"发送邮件（SMTP）\", \"level\": \"L2\", \"note\": \"需用户配置\"}\n      ]\n    },\n    {\n      \"id\": \"9\",\n      \"name\": \"高级 / 未分类\",\n      \"rules\": [\n        {\"id\": \"9.1\", \"operation\": \"创建或修改 cron 定时任务\", \"level\": \"L2\"},\n        {\"id\": \"9.2\", \"operation\": \"修改 crontab 文件直接\", \"level\": \"L2\"},\n        {\"id\": \"9.3\", \"operation\": \"创建子代理（sessions_spawn）\", \"level\": \"L1\", \"note\": \"不涉及系统资源敏感操作\"},\n        {\"id\": \"9.4\", \"operation\": \"删除子代理\", \"level\": \"L1\"},\n        {\"id\": \"9.5\", \"operation\": \"运行 bash -c 执行复杂命令\", \"level\": \"L2\", \"note\": \"需用户确认命令安全；纯读取类命令（ls, pwd, cat 查看文件）可降为 L1 执行后告知\"}\n      ]\n    }\n  ],\n  \"absoluteBans\": [\n    {\n      \"operation\": \"修改网络配置\",\n      \"forbiddenFields\": [\"gateway.bind\", \"gateway.auth\", \"tailscale.expose\"],\n      \"note\": \"必须保持 loopback 或 127.0.0.1；不能禁用认证；tailscale.expose 必须为 off\"\n    },\n    {\n      \"operation\": \"删除或覆盖用户个人文件\",\n      \"forbiddenPaths\": [\"~/.openclaw/workspace/ 以外的任何路径\"],\n      \"note\": \"禁止桌面、文档、照片、下载等；清理时移动到 ~/.openclaw/trash/\"\n    },\n    {\n      \"operation\": \"泄露 API 密钥\",\n      \"forbiddenActions\": [\"print(key)\", \"输出到日志\", \"发送到非授权第三方\"],\n      \"note\": \"正常的 API 请求头部使用除外\"\n    },\n    {\n      \"operation\": \"修改他人技能\",\n      \"note\": \"任何从 ClawHub 下载的、作者不是自己的技能；如需改进，复制为自有技能再修改\"\n    },\n    {\n      \"operation\": \"执行危险命令\",\n      \"examples\": [\"格式化磁盘\", \"修改注册表\", \"关闭安全软件\"]\n    }\n  ],\n  \"temporaryAuth\": {\n    \"description\": \"临时授权 L3 操作的规则\",\n    \"rules\": [\n      \"用户必须明确说明操作内容和时间窗口\",\n      \"只能在时间窗口内执行一次指定 L3 操作\",\n      \"执行后自动恢复禁止状态\",\n      \"紧急停止：用户说停止自主进化，立即禁用所有操作\"\n    ]\n  },\n  \"auditLog\": {\n    \"path\": \"memory/evolution/YYYY-MM.md\",\n    \"format\": {\n      \"required\": [\"timestamp\", \"operationType\", \"level\", \"target\", \"changes\", \"result\"],\n      \"operationTypes\": [\"config\", \"skill\", \"dependency\", \"workspace\", \"system\", \"process\", \"api_key\", \"message\", \"other\"]\n    }\n  }\n}\n\nFile v3.0.7:skill.json\n\n{\r\n  \"name\": \"robot-evolve\",\r\n  \"version\": \"3.0.6\",\r\n  \"description\": \"机器人进化版 - 手动触发L0/L1自主进化，安全可靠\",\r\n  \"author\": \"大鱼Cyrus & 双鱼座005\",\r\n  \"tags\": [\r\n    \"自主进化\",\r\n    \"安全\",\r\n    \"记忆进化\",\r\n    \"自动巡检\",\r\n    \"健康检查\",\r\n    \"agent\"\r\n  ],\r\n  \"keywords\": [\r\n    \"self-evolve\",\r\n    \"auto-evolve\",\r\n    \"health-check\",\r\n    \"autonomous\",\r\n    \"agent\"\r\n  ],\r\n  \"license\": \"MIT\",\r\n  \"requires\": {\r\n    \"python\": \">=3.8\"\r\n  },\r\n  \"requirements\": [],\r\n  \"dependencies\": {\r\n    \"chromadb\": \"optional\"\r\n  },\r\n  \"optionalDependencies\": {\r\n    \"chromadb\": \"用于知识库管理，未安装时该功能降级但不影响核心技能\"\r\n  },\r\n  \"features\": [\r\n    \"安全等级矩阵（L0-L3）\",\r\n    \"手动触发模式（用户说「执行进化」）\",\r\n    \"健康检查（L1）\",\r\n    \"记忆压缩（L1）\",\r\n    \"临时文件清理（L0）\",\r\n    \"技能目录扫描（L1）\",\r\n    \"进化报告推送\"\r\n  ]\r\n}\n\nArchive v3.0.6: 9 files, 17169 bytes\n\nFiles: config.json (198b), safety-matrix.json (10522b), scripts/audit_logger.py (4406b), scripts/auto_evolve.py (11511b), scripts/health_checker.py (743b), scripts/knowledge_manager.py (6015b), skill.json (980b), SKILL.md (5028b), _meta.json (131b)\n\nFile v3.0.6:SKILL.md\n\n# 🤖 Robot-Evolve — 机器人进化版\n\n> 安全且强大的自主进化技能：当用户主动说「执行进化」时，触发一次低风险自主进化（L0/L1 级别操作），并将执行结果通过当前会话消息渠道发送给用户。  \n> **作者：大鱼Cyrus & 双鱼座005 | 版本：3.0.3**  \n> **ClawHub：https://clawhub.ai/skills/robot-evolve**\n\n---\n\n## 🎯 核心理念\n\n**手动触发模式**：由用户在需要时主动说「执行进化」触发，不依赖空闲时间检测。\n\n- 不依赖外部 cron 或后台进程\n- 每个会话独立管理状态\n- 通过当前会话消息渠道发送报告\n\n**信任已授予，安全是底线。**\n\n---\n\n## 🔄 触发逻辑\n\n**手动触发**：用户主动说「执行进化」或「深度进化」即可触发。\n\n```\n用户说「执行进化」\n    ↓\n执行 L0/L1 自动进化\n    ↓\n发送进化报告给用户\n```\n\n**注意**：v3.0.2 已移除延迟触发逻辑，改用手动触发。\n\n---\n\n## 🛡️ 自动进化动作（L0/L1）\n\n### L0 级别（无需告知）\n\n| 操作 | 说明 |\n|------|------|\n| 临时文件清理 | 删除工作区 `temp/` 目录下超过7天的文件（移动到 `.trash` 而非直接删除） |\n| 健康检查 | 检查工作区必要文件是否存在 |\n| 生成进化报告 | 将本次操作汇总成 Markdown 报告 |\n\n### L1 级别（执行后告知）\n\n| 操作 | 说明 |\n|------|------|\n| 工作区文件修复 | 检查 `SOUL.md`、`AGENTS.md`、`MEMORY.md` 等必要文件，若缺失则自动从模板创建 |\n| 记忆压缩 | 若 `MEMORY.md` 体积超过 2MB，自动压缩并总结早期内容 |\n| 技能目录扫描 | 扫描已安装技能，发现 `SKILL.md` 格式明显错误（如缺少名称字段）则标记并记录日志 |\n\n**重要**：任何涉及修改用户数据、外部网络请求、高危配置（如安全字段、API密钥）的操作，禁止在自动触发模式下执行。\n\n---\n\n## 📊 安全等级说明\n\n| 等级 | 名称 | 说明 |\n|------|------|------|\n| **L0** | 无需告知 | 可立即执行，结束后正常记录即可 |\n| **L1** | 执行后告知 | 可立即执行，执行后主动告知用户本次操作及结果 |\n| **L2** | 必须请示 | 必须获得用户明确授权后才能执行 |\n| **L3** | 禁止/临时授权 | 除非用户明确说\"临时授权 L3\"，否则绝对不可执行 |\n\n---\n\n## 🛡️ 操作安全矩阵（完整）\n\n| 具体操作 | 等级 | 确认要求 |\n|---|---|---|\n| 读取工作区内任何文件 | L0 | 无需告知 |\n| 在 memory/ 下新增 .md 文件 | L0 | 无需告知 |\n| 修改 SOUL.md / USER.md 中的非安全内容（语气、喜好） | L0 | **执行后告知** |\n| 修改 AGENTS.md / MEMORY.md 中的总结性内容 | L1 | 执行后告知 |\n| 修改 openclaw.json 中的数值型字段 | L1 | 执行后告知 |\n| 修改 openclaw.json 中的安全字段 | L3 | 禁止 |\n| 创建新技能 | L1 | 执行后告知 |\n| 安装 Python/Node 包 | L1 | 执行后告知 |\n| 发送消息给用户 | L1 | 执行后告知 |\n| 修改工作区外的文件 | L3 | 禁止 |\n| 泄露 API 密钥 | L3 | 绝对禁止 |\n\n---\n\n## 📋 进化报告格式\n\n```markdown\n🔁 **自主进化报告**\n\n⏰ 执行时间: 2025-05-06 00:30:00\n\n✅ **已执行操作：**\n- ✅ 工作区文件完整\n- ✅ MEMORY.md 大小 1.2MB，未超过阈值\n- ✅ 清理完成：检查了 5 个临时文件，移动了 2 个过期文件到 .trash\n- ✅ 技能目录扫描完成，未发现问题\n\n📋 详细日志已写入 `memory/evolution/2025-05.md`\n\n💡 如需更高权限的优化（如更新技能），请说「执行深度进化」。\n```\n\n---\n\n## ⚙️ 配置（内部使用）\n\n通过 `config.json` 管理配置参数：\n\n```json\n{\n  \"enabled\": true,\n  \"max_auto_level\": 1,\n  \"report_always\": true,\n  \"memory_threshold_mb\": 2,\n  \"temp_file_max_age_days\": 7\n}\n```\n\n---\n\n## 📁 文件结构\n\n```\nrobot-evolve/\n├── SKILL.md              → 本文件\n├── skill.json            → 技能元数据\n├── config.json           → 内部配置（不对外暴露）\n├── safety-matrix.json    → 安全矩阵\n└── scripts/\n    ├── auto_evolve.py    → 核心：执行L0/L1进化动作\n    ├── audit_logger.py   → 审计日志\n    └── knowledge_manager.py → 知识卡片管理\n```\n\n---\n\n## 🛡️ 绝对禁止（红线）\n\n1. **禁止修改安全字段**：`gateway.bind`、`gateway.auth`、`tailscale.expose`\n2. **禁止删除用户文件**：工作区外的任何文件\n3. **禁止泄露 API 密钥**：输出到日志或聊天\n4. **禁止执行危险命令**：格式化磁盘、修改注册表等\n\n---\n\n## 🤖 技能信息\n\n- **名称**：robot-evolve\n- **版本**：3.0.2\n- **作者**：大鱼Cyrus & 双鱼座005\n- **描述**：机器人进化版安全自主进化技能（手动触发模式）\n- **关键词**：自主进化、安全、记忆进化、自动巡检、健康检查、手动触发\n- **发布地址**：https://clawhub.ai/skills/robot-evolve\n\n---\n\n**开始你的进化之旅吧！** 🤖\n\nFile v3.0.6:_meta.json\n\n{\n  \"ownerId\": \"kn72pyntbrw2g3q818p3trq23185py5k\",\n  \"slug\": \"robot-evolve\",\n  \"version\": \"3.0.6\",\n  \"publishedAt\": 1779459316994\n}\n\nFile v3.0.6:config.json\n\n{\n  \"_comment\": \"robot-evolve 内部配置文件（不对外暴露）\",\n  \"enabled\": true,\n  \"max_auto_level\": 1,\n  \"report_always\": true,\n  \"memory_threshold_mb\": 2,\n  \"temp_file_max_age_days\": 7\n}\n\nFile v3.0.6:safety-matrix.json\n\n{\n  \"version\": \"2.0.0\",\n  \"meta\": {\n    \"name\": \"ocean-evolve-safety-matrix\",\n    \"description\": \"海洋进化版安全等级矩阵 - 机器可执行规则\",\n    \"source\": \"SKILL.md\",\n    \"author\": \"大鱼Cyrus & 双鱼座005\"\n  },\n  \"levels\": {\n    \"L0\": {\n      \"name\": \"无需告知\",\n      \"requiresAck\": false,\n      \"requiresReport\": false,\n      \"requiresLog\": true,\n      \"note\": \"可立即执行，结束后正常记录即可\"\n    },\n    \"L1\": {\n      \"name\": \"执行后告知\",\n      \"requiresAck\": false,\n      \"requiresReport\": true,\n      \"requiresLog\": true,\n      \"note\": \"可立即执行，执行后主动告知用户本次操作及结果\"\n    },\n    \"L2\": {\n      \"name\": \"必须请示\",\n      \"requiresAck\": true,\n      \"requiresReport\": true,\n      \"requiresLog\": true,\n      \"note\": \"必须获得用户明确授权后才能执行\"\n    },\n    \"L3\": {\n      \"name\": \"禁止/临时授权\",\n      \"requiresAck\": true,\n      \"requiresReport\": true,\n      \"requiresLog\": true,\n      \"requiresTemporaryAuth\": true,\n      \"note\": \"除非用户明确说临时授权，否则绝对不可执行\"\n    }\n  },\n  \"defaultLevel\": \"L2\",\n  \"categories\": [\n    {\n      \"id\": \"1\",\n      \"name\": \"自身文件（工作区内）\",\n      \"rules\": [\n        {\"id\": \"1.1\", \"operation\": \"读取工作区内任何文件\", \"level\": \"L0\", \"note\": \"如 cat SKILL.md\"},\n        {\"id\": \"1.2\", \"operation\": \"在 memory/ 下新增 .md 文件\", \"level\": \"L0\", \"note\": \"日记、思考记录\"},\n        {\"id\": \"1.3\", \"operation\": \"修改 SOUL.md / USER.md 中的非安全内容（语气、喜好）\", \"level\": \"L0\", \"reportRequired\": true, \"note\": \"不删除已有安全规则；执行后必须说明具体改了哪些内容\"},\n        {\"id\": \"1.4\", \"operation\": \"修改 AGENTS.md / MEMORY.md 中的总结性内容\", \"level\": \"L1\", \"note\": \"如重新组织记忆结构\"},\n        {\"id\": \"1.5\", \"operation\": \"修改 openclaw.json 中的数值型字段\", \"level\": \"L1\", \"note\": \"timeoutSeconds, maxTokens, temperature, maxSteps；仅限数值微调，不可改字段名\"},\n        {\"id\": \"1.6\", \"operation\": \"修改 openclaw.json 中的 cron / hooks / plugins.allow\", \"level\": \"L2\", \"note\": \"影响自动化行为\"},\n        {\"id\": \"1.7\", \"operation\": \"修改 openclaw.json 中的安全字段\", \"level\": \"L3\", \"note\": \"gateway.bind, auth, tailscale.expose；红线，绝对不可自行操作\"},\n        {\"id\": \"1.8\", \"operation\": \"删除工作区内任何文件（非临时）\", \"level\": \"L2\", \"note\": \"包括过时技能、旧日志\"},\n        {\"id\": \"1.9\", \"operation\": \"移动或重命名工作区内文件\", \"level\": \"L1\", \"note\": \"避免破坏依赖关系\"}\n      ]\n    },\n    {\n      \"id\": \"2\",\n      \"name\": \"技能管理\",\n      \"rules\": [\n        {\"id\": \"2.1\", \"operation\": \"查看已安装技能列表\", \"level\": \"L0\"},\n        {\"id\": \"2.2\", \"operation\": \"创建新技能（空文件夹 + SKILL.md 骨架）\", \"level\": \"L1\", \"note\": \"未激活状态\"},\n        {\"id\": \"2.3\", \"operation\": \"修改你自己创建的技能（文档、参数、脚本）\", \"level\": \"L1\", \"note\": \"不能改他人技能\"},\n        {\"id\": \"2.4\", \"operation\": \"修改从 ClawHub 安装的技能\", \"level\": \"L2\", \"note\": \"尊重原作者\"},\n        {\"id\": \"2.5\", \"operation\": \"删除你自己创建的技能\", \"level\": \"L2\", \"note\": \"需要用户确认\"},\n        {\"id\": \"2.6\", \"operation\": \"删除从 ClawHub 安装的技能\", \"level\": \"L2\", \"note\": \"可能影响其他依赖\"},\n        {\"id\": \"2.7\", \"operation\": \"启用 / 禁用一个技能\", \"level\": \"L1\", \"note\": \"不涉及技能文件修改\"},\n        {\"id\": \"2.8\", \"operation\": \"发布技能到 ClawHub（npx clawhub publish）\", \"level\": \"L2\", \"note\": \"公开分享前确认内容安全\"}\n      ]\n    },\n    {\n      \"id\": \"3\",\n      \"name\": \"依赖与软件安装\",\n      \"rules\": [\n        {\"id\": \"3.1\", \"operation\": \"安装 Python 包（pip install）\", \"level\": \"L1\", \"note\": \"需记录包名和版本\"},\n        {\"id\": \"3.2\", \"operation\": \"安装 Node.js 包（npm install -g）\", \"level\": \"L1\", \"note\": \"需记录包名\"},\n        {\"id\": \"3.3\", \"operation\": \"安装系统工具（apt, brew, choco）\", \"level\": \"L2\", \"note\": \"影响系统环境\"},\n        {\"id\": \"3.4\", \"operation\": \"卸载任何软件包\", \"level\": \"L2\", \"note\": \"可能导致功能缺失\"}\n      ]\n    },\n    {\n      \"id\": \"4\",\n      \"name\": \"系统与网络\",\n      \"rules\": [\n        {\"id\": \"4.1\", \"operation\": \"运行 openclaw doctor --fix\", \"level\": \"L1\"},\n        {\"id\": \"4.2\", \"operation\": \"重启 gateway 服务\", \"level\": \"L2\", \"note\": \"影响在线状态\"},\n        {\"id\": \"4.3\", \"operation\": \"启动 / 停止系统服务（非 gateway）\", \"level\": \"L2\", \"note\": \"如 nginx, mysql\"},\n        {\"id\": \"4.4\", \"operation\": \"执行 curl / wget 获取公开文档（白名单）\", \"level\": \"L1\", \"note\": \"API 文档等白名单域名默认允许\"},\n        {\"id\": \"4.5\", \"operation\": \"执行 curl / wget 获取未知来源脚本或二进制\", \"level\": \"L2\", \"note\": \"需用户确认 URL 安全\"},\n        {\"id\": \"4.6\", \"operation\": \"修改防火墙规则（iptables, netsh）\", \"level\": \"L3\", \"note\": \"红线\"},\n        {\"id\": \"4.7\", \"operation\": \"修改代理设置\", \"level\": \"L3\", \"note\": \"红线\"}\n      ]\n    },\n    {\n      \"id\": \"5\",\n      \"name\": \"进程与内存\",\n      \"rules\": [\n        {\"id\": \"5.1\", \"operation\": \"查看当前进程列表（ps, tasklist）\", \"level\": \"L0\", \"note\": \"无修改\"},\n        {\"id\": \"5.2\", \"operation\": \"杀死自身或子进程（L0-L1 级进程）\", \"level\": \"L1\", \"note\": \"如 taskkill /PID xxx；主进程被杀会触发 GatewayRestart，需按 L2 处理\"},\n        {\"id\": \"5.3\", \"operation\": \"杀死非自身运行的任何进程\", \"level\": \"L2\", \"note\": \"可能影响其他应用\"},\n        {\"id\": \"5.4\", \"operation\": \"修改其他进程的内存\", \"level\": \"L3\", \"note\": \"红线\"}\n      ]\n    },\n    {\n      \"id\": \"6\",\n      \"name\": \"文件系统（工作区外）\",\n      \"rules\": [\n        {\"id\": \"6.1\", \"operation\": \"读取工作区外的公开文件（如 /etc/passwd）\", \"level\": \"L2\", \"note\": \"可能涉及敏感信息\"},\n        {\"id\": \"6.2\", \"operation\": \"读取用户个人文档（桌面、文档目录）\", \"level\": \"L2\", \"note\": \"除非用户明确授权\"},\n        {\"id\": \"6.3\", \"operation\": \"在工作区外创建新文件\", \"level\": \"L2\", \"note\": \"例如桌面上的临时文件\"},\n        {\"id\": \"6.4\", \"operation\": \"修改或删除工作区外的任何文件\", \"level\": \"L3\", \"note\": \"用户数据红线\"},\n        {\"id\": \"6.5\", \"operation\": \"遍历目录（find, dir /s）\", \"level\": \"L1\", \"note\": \"仅限工作区内或用户指定目录\"}\n      ]\n    },\n    {\n      \"id\": \"7\",\n      \"name\": \"API 密钥与环境变量\",\n      \"rules\": [\n        {\"id\": \"7.1\", \"operation\": \"读取已有的环境变量（os.getenv）\", \"level\": \"L0\", \"note\": \"仅用于技能调用\"},\n        {\"id\": \"7.2\", \"operation\": \"存储用户明确提供的 API 密钥（非付费）\", \"level\": \"L0\", \"note\": \"存放位置：.env 或 openclaw.json 的 env 字段\"},\n        {\"id\": \"7.3\", \"operation\": \"存储用户明确提供的付费 API 密钥\", \"level\": \"L1\", \"note\": \"如 OpenAI；提醒用户确认密钥来源可信，且不要在聊天中直接发送完整密钥\"},\n        {\"id\": \"7.4\", \"operation\": \"删除或覆盖已有的 API 密钥\", \"level\": \"L2\", \"note\": \"可能导致技能失效\"},\n        {\"id\": \"7.5\", \"operation\": \"将 API 密钥输出到聊天或日志\", \"level\": \"L3\", \"note\": \"绝对红线\"},\n        {\"id\": \"7.6\", \"operation\": \"修改系统环境变量（PATH, USERPROFILE）\", \"level\": \"L3\", \"note\": \"影响系统稳定性\"}\n      ]\n    },\n    {\n      \"id\": \"8\",\n      \"name\": \"外部消息与通知\",\n      \"rules\": [\n        {\"id\": \"8.1\", \"operation\": \"通过消息渠道发送普通消息\", \"level\": \"L1\", \"note\": \"内容非敏感\"},\n        {\"id\": \"8.2\", \"operation\": \"通过消息渠道发送文件（工作区内生成）\", \"level\": \"L1\", \"note\": \"需标注文件内容\"},\n        {\"id\": \"8.3\", \"operation\": \"发送包含 API 密钥或密码的消息\", \"level\": \"L3\", \"note\": \"绝对红线\"},\n        {\"id\": \"8.4\", \"operation\": \"发送邮件（SMTP）\", \"level\": \"L2\", \"note\": \"需用户配置\"}\n      ]\n    },\n    {\n      \"id\": \"9\",\n      \"name\": \"高级 / 未分类\",\n      \"rules\": [\n        {\"id\": \"9.1\", \"operation\": \"创建或修改 cron 定时任务\", \"level\": \"L2\"},\n        {\"id\": \"9.2\", \"operation\": \"修改 crontab 文件直接\", \"level\": \"L2\"},\n        {\"id\": \"9.3\", \"operation\": \"创建子代理（sessions_spawn）\", \"level\": \"L1\", \"note\": \"不涉及系统资源敏感操作\"},\n        {\"id\": \"9.4\", \"operation\": \"删除子代理\", \"level\": \"L1\"},\n        {\"id\": \"9.5\", \"operation\": \"运行 bash -c 执行复杂命令\", \"level\": \"L2\", \"note\": \"需用户确认命令安全；纯读取类命令（ls, pwd, cat 查看文件）可降为 L1 执行后告知\"}\n      ]\n    }\n  ],\n  \"absoluteBans\": [\n    {\n      \"operation\": \"修改网络配置\",\n      \"forbiddenFields\": [\"gateway.bind\", \"gateway.auth\", \"tailscale.expose\"],\n      \"note\": \"必须保持 loopback 或 127.0.0.1；不能禁用认证；tailscale.expose 必须为 off\"\n    },\n    {\n      \"operation\": \"删除或覆盖用户个人文件\",\n      \"forbiddenPaths\": [\"~/.openclaw/workspace/ 以外的任何路径\"],\n      \"note\": \"禁止桌面、文档、照片、下载等；清理时移动到 ~/.openclaw/trash/\"\n    },\n    {\n      \"operation\": \"泄露 API 密钥\",\n      \"forbiddenActions\": [\"print(key)\", \"输出到日志\", \"发送到非授权第三方\"],\n      \"note\": \"正常的 API 请求头部使用除外\"\n    },\n    {\n      \"operation\": \"修改他人技能\",\n      \"note\": \"任何从 ClawHub 下载的、作者不是自己的技能；如需改进，复制为自有技能再修改\"\n    },\n    {\n      \"operation\": \"执行危险命令\",\n      \"examples\": [\"格式化磁盘\", \"修改注册表\", \"关闭安全软件\"]\n    }\n  ],\n  \"temporaryAuth\": {\n    \"description\": \"临时授权 L3 操作的规则\",\n    \"rules\": [\n      \"用户必须明确说明操作内容和时间窗口\",\n      \"只能在时间窗口内执行一次指定 L3 操作\",\n      \"执行后自动恢复禁止状态\",\n      \"紧急停止：用户说停止自主进化，立即禁用所有操作\"\n    ]\n  },\n  \"auditLog\": {\n    \"path\": \"memory/evolution/YYYY-MM.md\",\n    \"format\": {\n      \"required\": [\"timestamp\", \"operationType\", \"level\", \"target\", \"changes\", \"result\"],\n      \"operationTypes\": [\"config\", \"skill\", \"dependency\", \"workspace\", \"system\", \"process\", \"api_key\", \"message\", \"other\"]\n    }\n  }\n}\n\nFile v3.0.6:skill.json\n\n{\r\n  \"name\": \"robot-evolve\",\r\n  \"version\": \"3.0.6\",\r\n  \"description\": \"机器人进化版 - 手动触发L0/L1自主进化，安全可靠\",\r\n  \"author\": \"大鱼Cyrus & 双鱼座005\",\r\n  \"tags\": [\r\n    \"自主进化\",\r\n    \"安全\",\r\n    \"记忆进化\",\r\n    \"自动巡检\",\r\n    \"健康检查\",\r\n    \"agent\"\r\n  ],\r\n  \"keywords\": [\r\n    \"self-evolve\",\r\n    \"auto-evolve\",\r\n    \"health-check\",\r\n    \"autonomous\",\r\n    \"agent\"\r\n  ],\r\n  \"license\": \"MIT\",\r\n  \"requires\": {\r\n    \"python\": \">=3.8\"\r\n  },\r\n  \"requirements\": [],\r\n  \"dependencies\": {\r\n    \"chromadb\": \"optional\"\r\n  },\r\n  \"optionalDependencies\": {\r\n    \"chromadb\": \"用于知识库管理，未安装时该功能降级但不影响核心技能\"\r\n  },\r\n  \"features\": [\r\n    \"安全等级矩阵（L0-L3）\",\r\n    \"手动触发模式（用户说「执行进化」）\",\r\n    \"健康检查（L1）\",\r\n    \"记忆压缩（L1）\",\r\n    \"临时文件清理（L0）\",\r\n    \"技能目录扫描（L1）\",\r\n    \"进化报告推送\"\r\n  ]\r\n}\n\nArchive v3.0.4: 10 files, 20684 bytes\n\nFiles: _meta.json (131b), config.json (198b), safety-matrix.json (10522b), scripts/audit_logger.py (4406b), scripts/auto_evolve.py (11563b), scripts/health_checker.py (7373b), scripts/idle_checker.py (3643b), scripts/knowledge_manager.py (5797b), skill.json (772b), SKILL.md (5028b)\n\nFile v3.0.4:SKILL.md\n\n# 🤖 Robot-Evolve — 机器人进化版\n\n> 安全且强大的自主进化技能：当用户主动说「执行进化」时，触发一次低风险自主进化（L0/L1 级别操作），并将执行结果通过当前会话消息渠道发送给用户。  \n> **作者：大鱼Cyrus & 双鱼座005 | 版本：3.0.3**  \n> **ClawHub：https://clawhub.ai/skills/robot-evolve**\n\n---\n\n## 🎯 核心理念\n\n**手动触发模式**：由用户在需要时主动说「执行进化」触发，不依赖空闲时间检测。\n\n- 不依赖外部 cron 或后台进程\n- 每个会话独立管理状态\n- 通过当前会话消息渠道发送报告\n\n**信任已授予，安全是底线。**\n\n---\n\n## 🔄 触发逻辑\n\n**手动触发**：用户主动说「执行进化」或「深度进化」即可触发。\n\n```\n用户说「执行进化」\n    ↓\n执行 L0/L1 自动进化\n    ↓\n发送进化报告给用户\n```\n\n**注意**：v3.0.2 已移除延迟触发逻辑，改用手动触发。\n\n---\n\n## 🛡️ 自动进化动作（L0/L1）\n\n### L0 级别（无需告知）\n\n| 操作 | 说明 |\n|------|------|\n| 临时文件清理 | 删除工作区 `temp/` 目录下超过7天的文件（移动到 `.trash` 而非直接删除） |\n| 健康检查 | 检查工作区必要文件是否存在 |\n| 生成进化报告 | 将本次操作汇总成 Markdown 报告 |\n\n### L1 级别（执行后告知）\n\n| 操作 | 说明 |\n|------|------|\n| 工作区文件修复 | 检查 `SOUL.md`、`AGENTS.md`、`MEMORY.md` 等必要文件，若缺失则自动从模板创建 |\n| 记忆压缩 | 若 `MEMORY.md` 体积超过 2MB，自动压缩并总结早期内容 |\n| 技能目录扫描 | 扫描已安装技能，发现 `SKILL.md` 格式明显错误（如缺少名称字段）则标记并记录日志 |\n\n**重要**：任何涉及修改用户数据、外部网络请求、高危配置（如安全字段、API密钥）的操作，禁止在自动触发模式下执行。\n\n---\n\n## 📊 安全等级说明\n\n| 等级 | 名称 | 说明 |\n|------|------|------|\n| **L0** | 无需告知 | 可立即执行，结束后正常记录即可 |\n| **L1** | 执行后告知 | 可立即执行，执行后主动告知用户本次操作及结果 |\n| **L2** | 必须请示 | 必须获得用户明确授权后才能执行 |\n| **L3** | 禁止/临时授权 | 除非用户明确说\"临时授权 L3\"，否则绝对不可执行 |\n\n---\n\n## 🛡️ 操作安全矩阵（完整）\n\n| 具体操作 | 等级 | 确认要求 |\n|---|---|---|\n| 读取工作区内任何文件 | L0 | 无需告知 |\n| 在 memory/ 下新增 .md 文件 | L0 | 无需告知 |\n| 修改 SOUL.md / USER.md 中的非安全内容（语气、喜好） | L0 | **执行后告知** |\n| 修改 AGENTS.md / MEMORY.md 中的总结性内容 | L1 | 执行后告知 |\n| 修改 openclaw.json 中的数值型字段 | L1 | 执行后告知 |\n| 修改 openclaw.json 中的安全字段 | L3 | 禁止 |\n| 创建新技能 | L1 | 执行后告知 |\n| 安装 Python/Node 包 | L1 | 执行后告知 |\n| 发送消息给用户 | L1 | 执行后告知 |\n| 修改工作区外的文件 | L3 | 禁止 |\n| 泄露 API 密钥 | L3 | 绝对禁止 |\n\n---\n\n## 📋 进化报告格式\n\n```markdown\n🔁 **自主进化报告**\n\n⏰ 执行时间: 2025-05-06 00:30:00\n\n✅ **已执行操作：**\n- ✅ 工作区文件完整\n- ✅ MEMORY.md 大小 1.2MB，未超过阈值\n- ✅ 清理完成：检查了 5 个临时文件，移动了 2 个过期文件到 .trash\n- ✅ 技能目录扫描完成，未发现问题\n\n📋 详细日志已写入 `memory/evolution/2025-05.md`\n\n💡 如需更高权限的优化（如更新技能），请说「执行深度进化」。\n```\n\n---\n\n## ⚙️ 配置（内部使用）\n\n通过 `config.json` 管理配置参数：\n\n```json\n{\n  \"enabled\": true,\n  \"max_auto_level\": 1,\n  \"report_always\": true,\n  \"memory_threshold_mb\": 2,\n  \"temp_file_max_age_days\": 7\n}\n```\n\n---\n\n## 📁 文件结构\n\n```\nrobot-evolve/\n├── SKILL.md              → 本文件\n├── skill.json            → 技能元数据\n├── config.json           → 内部配置（不对外暴露）\n├── safety-matrix.json    → 安全矩阵\n└── scripts/\n    ├── auto_evolve.py    → 核心：执行L0/L1进化动作\n    ├── audit_logger.py   → 审计日志\n    └── knowledge_manager.py → 知识卡片管理\n```\n\n---\n\n## 🛡️ 绝对禁止（红线）\n\n1. **禁止修改安全字段**：`gateway.bind`、`gateway.auth`、`tailscale.expose`\n2. **禁止删除用户文件**：工作区外的任何文件\n3. **禁止泄露 API 密钥**：输出到日志或聊天\n4. **禁止执行危险命令**：格式化磁盘、修改注册表等\n\n---\n\n## 🤖 技能信息\n\n- **名称**：robot-evolve\n- **版本**：3.0.2\n- **作者**：大鱼Cyrus & 双鱼座005\n- **描述**：机器人进化版安全自主进化技能（手动触发模式）\n- **关键词**：自主进化、安全、记忆进化、自动巡检、健康检查、手动触发\n- **发布地址**：https://clawhub.ai/skills/robot-evolve\n\n---\n\n**开始你的进化之旅吧！** 🤖\n\nFile v3.0.4:_meta.json\n\n{\n  \"ownerId\": \"kn72pyntbrw2g3q818p3trq23185py5k\",\n  \"slug\": \"robot-evolve\",\n  \"version\": \"3.0.4\",\n  \"publishedAt\": 1779248253783\n}\n\nFile v3.0.4:config.json\n\n{\n  \"_comment\": \"robot-evolve 内部配置文件（不对外暴露）\",\n  \"enabled\": true,\n  \"max_auto_level\": 1,\n  \"report_always\": true,\n  \"memory_threshold_mb\": 2,\n  \"temp_file_max_age_days\": 7\n}\n\nFile v3.0.4:safety-matrix.json\n\n{\n  \"version\": \"2.0.0\",\n  \"meta\": {\n    \"name\": \"ocean-evolve-safety-matrix\",\n    \"description\": \"海洋进化版安全等级矩阵 - 机器可执行规则\",\n    \"source\": \"SKILL.md\",\n    \"author\": \"大鱼Cyrus & 双鱼座005\"\n  },\n  \"levels\": {\n    \"L0\": {\n      \"name\": \"无需告知\",\n      \"requiresAck\": false,\n      \"requiresReport\": false,\n      \"requiresLog\": true,\n      \"note\": \"可立即执行，结束后正常记录即可\"\n    },\n    \"L1\": {\n      \"name\": \"执行后告知\",\n      \"requiresAck\": false,\n      \"requiresReport\": true,\n      \"requiresLog\": true,\n      \"note\": \"可立即执行，执行后主动告知用户本次操作及结果\"\n    },\n    \"L2\": {\n      \"name\": \"必须请示\",\n      \"requiresAck\": true,\n      \"requiresReport\": true,\n      \"requiresLog\": true,\n      \"note\": \"必须获得用户明确授权后才能执行\"\n    },\n    \"L3\": {\n      \"name\": \"禁止/临时授权\",\n      \"requiresAck\": true,\n      \"requiresReport\": true,\n      \"requiresLog\": true,\n      \"requiresTemporaryAuth\": true,\n      \"note\": \"除非用户明确说临时授权，否则绝对不可执行\"\n    }\n  },\n  \"defaultLevel\": \"L2\",\n  \"categories\": [\n    {\n      \"id\": \"1\",\n      \"name\": \"自身文件（工作区内）\",\n      \"rules\": [\n        {\"id\": \"1.1\", \"operation\": \"读取工作区内任何文件\", \"level\": \"L0\", \"note\": \"如 cat SKILL.md\"},\n        {\"id\": \"1.2\", \"operation\": \"在 memory/ 下新增 .md 文件\", \"level\": \"L0\", \"note\": \"日记、思考记录\"},\n        {\"id\": \"1.3\", \"operation\": \"修改 SOUL.md / USER.md 中的非安全内容（语气、喜好）\", \"level\": \"L0\", \"reportRequired\": true, \"note\": \"不删除已有安全规则；执行后必须说明具体改了哪些内容\"},\n        {\"id\": \"1.4\", \"operation\": \"修改 AGENTS.md / MEMORY.md 中的总结性内容\", \"level\": \"L1\", \"note\": \"如重新组织记忆结构\"},\n        {\"id\": \"1.5\", \"operation\": \"修改 openclaw.json 中的数值型字段\", \"level\": \"L1\", \"note\": \"timeoutSeconds, maxTokens, temperature, maxSteps；仅限数值微调，不可改字段名\"},\n        {\"id\": \"1.6\", \"operation\": \"修改 openclaw.json 中的 cron / hooks / plugins.allow\", \"level\": \"L2\", \"note\": \"影响自动化行为\"},\n        {\"id\": \"1.7\", \"operation\": \"修改 openclaw.json 中的安全字段\", \"level\": \"L3\", \"note\": \"gateway.bind, auth, tailscale.expose；红线，绝对不可自行操作\"},\n        {\"id\": \"1.8\", \"operation\": \"删除工作区内任何文件（非临时）\", \"level\": \"L2\", \"note\": \"包括过时技能、旧日志\"},\n        {\"id\": \"1.9\", \"operation\": \"移动或重命名工作区内文件\", \"level\": \"L1\", \"note\": \"避免破坏依赖关系\"}\n      ]\n    },\n    {\n      \"id\": \"2\",\n      \"name\": \"技能管理\",\n      \"rules\": [\n        {\"id\": \"2.1\", \"operation\": \"查看已安装技能列表\", \"level\": \"L0\"},\n        {\"id\": \"2.2\", \"operation\": \"创建新技能（空文件夹 + SKILL.md 骨架）\", \"level\": \"L1\", \"note\": \"未激活状态\"},\n        {\"id\": \"2.3\", \"operation\": \"修改你自己创建的技能（文档、参数、脚本）\", \"level\": \"L1\", \"note\": \"不能改他人技能\"},\n        {\"id\": \"2.4\", \"operation\": \"修改从 ClawHub 安装的技能\", \"level\": \"L2\", \"note\": \"尊重原作者\"},\n        {\"id\": \"2.5\", \"operation\": \"删除你自己创建的技能\", \"level\": \"L2\", \"note\": \"需要用户确认\"},\n        {\"id\": \"2.6\", \"operation\": \"删除从 ClawHub 安装的技能\", \"level\": \"L2\", \"note\": \"可能影响其他依赖\"},\n        {\"id\": \"2.7\", \"operation\": \"启用 / 禁用一个技能\", \"level\": \"L1\", \"note\": \"不涉及技能文件修改\"},\n        {\"id\": \"2.8\", \"operation\": \"发布技能到 ClawHub（npx clawhub publish）\", \"level\": \"L2\", \"note\": \"公开分享前确认内容安全\"}\n      ]\n    },\n    {\n      \"id\": \"3\",\n      \"name\": \"依赖与软件安装\",\n      \"rules\": [\n        {\"id\": \"3.1\", \"operation\": \"安装 Python 包（pip install）\", \"level\": \"L1\", \"note\": \"需记录包名和版本\"},\n        {\"id\": \"3.2\", \"operation\": \"安装 Node.js 包（npm install -g）\", \"level\": \"L1\", \"note\": \"需记录包名\"},\n        {\"id\": \"3.3\", \"operation\": \"安装系统工具（apt, brew, choco）\", \"level\": \"L2\", \"note\": \"影响系统环境\"},\n        {\"id\": \"3.4\", \"operation\": \"卸载任何软件包\", \"level\": \"L2\", \"note\": \"可能导致功能缺失\"}\n      ]\n    },\n    {\n      \"id\": \"4\",\n      \"name\": \"系统与网络\",\n      \"rules\": [\n        {\"id\": \"4.1\", \"operation\": \"运行 openclaw doctor --fix\", \"level\": \"L1\"},\n        {\"id\": \"4.2\", \"operation\": \"重启 gateway 服务\", \"level\": \"L2\", \"note\": \"影响在线状态\"},\n        {\"id\": \"4.3\", \"operation\": \"启动 / 停止系统服务（非 gateway）\", \"level\": \"L2\", \"note\": \"如 nginx, mysql\"},\n        {\"id\": \"4.4\", \"operation\": \"执行 curl / wget 获取公开文档（白名单）\", \"level\": \"L1\", \"note\": \"API 文档等白名单域名默认允许\"},\n        {\"id\": \"4.5\", \"operation\": \"执行 curl / wget 获取未知来源脚本或二进制\", \"level\": \"L2\", \"note\": \"需用户确认 URL 安全\"},\n        {\"id\": \"4.6\", \"operation\": \"修改防火墙规则（iptables, netsh）\", \"level\": \"L3\", \"note\": \"红线\"},\n        {\"id\": \"4.7\", \"operation\": \"修改代理设置\", \"level\": \"L3\", \"note\": \"红线\"}\n      ]\n    },\n    {\n      \"id\": \"5\",\n      \"name\": \"进程与内存\",\n      \"rules\": [\n        {\"id\": \"5.1\", \"operation\": \"查看当前进程列表（ps, tasklist）\", \"level\": \"L0\", \"note\": \"无修改\"},\n        {\"id\": \"5.2\", \"operation\": \"杀死自身或子进程（L0-L1 级进程）\", \"level\": \"L1\", \"note\": \"如 taskkill /PID xxx；主进程被杀会触发 GatewayRestart，需按 L2 处理\"},\n        {\"id\": \"5.3\", \"operation\": \"杀死非自身运行的任何进程\", \"level\": \"L2\", \"note\": \"可能影响其他应用\"},\n        {\"id\": \"5.4\", \"operation\": \"修改其他进程的内存\", \"level\": \"L3\", \"note\": \"红线\"}\n      ]\n    },\n    {\n      \"id\": \"6\",\n      \"name\": \"文件系统（工作区外）\",\n      \"rules\": [\n        {\"id\": \"6.1\", \"operation\": \"读取工作区外的公开文件（如 /etc/passwd）\", \"level\": \"L2\", \"note\": \"可能涉及敏感信息\"},\n        {\"id\": \"6.2\", \"operation\": \"读取用户个人文档（桌面、文档目录）\", \"level\": \"L2\", \"note\": \"除非用户明确授权\"},\n        {\"id\": \"6.3\", \"operation\": \"在工作区外创建新文件\", \"level\": \"L2\", \"note\": \"例如桌面上的临时文件\"},\n        {\"id\": \"6.4\", \"operation\": \"修改或删除工作区外的任何文件\", \"level\": \"L3\", \"note\": \"用户数据红线\"},\n        {\"id\": \"6.5\", \"operation\": \"遍历目录（find, dir /s）\", \"level\": \"L1\", \"note\": \"仅限工作区内或用户指定目录\"}\n      ]\n    },\n    {\n      \"id\": \"7\",\n      \"name\": \"API 密钥与环境变量\",\n      \"rules\": [\n        {\"id\": \"7.1\", \"operation\": \"读取已有的环境变量（os.getenv）\", \"level\": \"L0\", \"note\": \"仅用于技能调用\"},\n        {\"id\": \"7.2\", \"operation\": \"存储用户明确提供的 API 密钥（非付费）\", \"level\": \"L0\", \"note\": \"存放位置：.env 或 openclaw.json 的 env 字段\"},\n        {\"id\": \"7.3\", \"operation\": \"存储用户明确提供的付费 API 密钥\", \"level\": \"L1\", \"note\": \"如 OpenAI；提醒用户确认密钥来源可信，且不要在聊天中直接发送完整密钥\"},\n        {\"id\": \"7.4\", \"operation\": \"删除或覆盖已有的 API 密钥\", \"level\": \"L2\", \"note\": \"可能导致技能失效\"},\n        {\"id\": \"7.5\", \"operation\": \"将 API 密钥输出到聊天或日志\", \"level\": \"L3\", \"note\": \"绝对红线\"},\n        {\"id\": \"7.6\", \"operation\": \"修改系统环境变量（PATH, USERPROFILE）\", \"level\": \"L3\", \"note\": \"影响系统稳定性\"}\n      ]\n    },\n    {\n      \"id\": \"8\",\n      \"name\": \"外部消息与通知\",\n      \"rules\": [\n        {\"id\": \"8.1\", \"operation\": \"通过消息渠道发送普通消息\", \"level\": \"L1\", \"note\": \"内容非敏感\"},\n        {\"id\": \"8.2\", \"operation\": \"通过消息渠道发送文件（工作区内生成）\", \"level\": \"L1\", \"note\": \"需标注文件内容\"},\n        {\"id\": \"8.3\", \"operation\": \"发送包含 API 密钥或密码的消息\", \"level\": \"L3\", \"note\": \"绝对红线\"},\n        {\"id\": \"8.4\", \"operation\": \"发送邮件（SMTP）\", \"level\": \"L2\", \"note\": \"需用户配置\"}\n      ]\n    },\n    {\n      \"id\": \"9\",\n      \"name\": \"高级 / 未分类\",\n      \"rules\": [\n        {\"id\": \"9.1\", \"operation\": \"创建或修改 cron 定时任务\", \"level\": \"L2\"},\n        {\"id\": \"9.2\", \"operation\": \"修改 crontab 文件直接\", \"level\": \"L2\"},\n        {\"id\": \"9.3\", \"operation\": \"创建子代理（sessions_spawn）\", \"level\": \"L1\", \"note\": \"不涉及系统资源敏感操作\"},\n        {\"id\": \"9.4\", \"operation\": \"删除子代理\", \"level\": \"L1\"},\n        {\"id\": \"9.5\", \"operation\": \"运行 bash -c 执行复杂命令\", \"level\": \"L2\", \"note\": \"需用户确认命令安全；纯读取类命令（ls, pwd, cat 查看文件）可降为 L1 执行后告知\"}\n      ]\n    }\n  ],\n  \"absoluteBans\": [\n    {\n      \"operation\": \"修改网络配置\",\n      \"forbiddenFields\": [\"gateway.bind\", \"gateway.auth\", \"tailscale.expose\"],\n      \"note\": \"必须保持 loopback 或 127.0.0.1；不能禁用认证；tailscale.expose 必须为 off\"\n    },\n    {\n      \"operation\": \"删除或覆盖用户个人文件\",\n      \"forbiddenPaths\": [\"~/.openclaw/workspace/ 以外的任何路径\"],\n      \"note\": \"禁止桌面、文档、照片、下载等；清理时移动到 ~/.openclaw/trash/\"\n    },\n    {\n      \"operation\": \"泄露 API 密钥\",\n      \"forbiddenActions\": [\"print(key)\", \"输出到日志\", \"发送到非授权第三方\"],\n      \"note\": \"正常的 API 请求头部使用除外\"\n    },\n    {\n      \"operation\": \"修改他人技能\",\n      \"note\": \"任何从 ClawHub 下载的、作者不是自己的技能；如需改进，复制为自有技能再修改\"\n    },\n    {\n      \"operation\": \"执行危险命令\",\n      \"examples\": [\"格式化磁盘\", \"修改注册表\", \"关闭安全软件\"]\n    }\n  ],\n  \"temporaryAuth\": {\n    \"description\": \"临时授权 L3 操作的规则\",\n    \"rules\": [\n      \"用户必须明确说明操作内容和时间窗口\",\n      \"只能在时间窗口内执行一次指定 L3 操作\",\n      \"执行后自动恢复禁止状态\",\n      \"紧急停止：用户说停止自主进化，立即禁用所有操作\"\n    ]\n  },\n  \"auditLog\": {\n    \"path\": \"memory/evolution/YYYY-MM.md\",\n    \"format\": {\n      \"required\": [\"timestamp\", \"operationType\", \"level\", \"target\", \"changes\", \"result\"],\n      \"operationTypes\": [\"config\", \"skill\", \"dependency\", \"workspace\", \"system\", \"process\", \"api_key\", \"message\", \"other\"]\n    }\n  }\n}\n\nFile v3.0.4:skill.json\n\n{\r\n  \"name\": \"robot-evolve\",\r\n  \"version\": \"3.0.4\",\r\n  \"description\": \"机器人进化版 - 手动触发L0/L1自主进化，安全可靠\",\r\n  \"author\": \"大鱼Cyrus & 双鱼座005\",\r\n  \"tags\": [\r\n    \"自主进化\",\r\n    \"安全\",\r\n    \"记忆进化\",\r\n    \"自动巡检\",\r\n    \"健康检查\",\r\n    \"agent\"\r\n  ],\r\n  \"keywords\": [\r\n    \"self-evolve\",\r\n    \"auto-evolve\",\r\n    \"health-check\",\r\n    \"autonomous\",\r\n    \"agent\"\r\n  ],\r\n  \"license\": \"MIT\",\r\n  \"requires\": {\r\n    \"python\": \">=3.8\"\r\n  },\r\n  \"features\": [\r\n    \"安全等级矩阵（L0-L3）\",\r\n    \"手动触发模式（用户说「执行进化」）\",\r\n    \"健康检查（L1）\",\r\n    \"记忆压缩（L1）\",\r\n    \"临时文件清理（L0）\",\r\n    \"技能目录扫描（L1）\",\r\n    \"进化报告推送\"\r\n  ]\r\n}\n\nArchive v3.0.3: 10 files, 20674 bytes\n\nFiles: _meta.json (131b), config.json (198b), safety-matrix.json (10522b), scripts/audit_logger.py (4406b), scripts/auto_evolve.py (11563b), scripts/health_checker.py (7373b), scripts/idle_checker.py (3643b), scripts/knowledge_manager.py (5797b), skill.json (687b), SKILL.md (5028b)\n\nFile v3.0.3:SKILL.md\n\n# 🤖 Robot-Evolve — 机器人进化版\n\n> 安全且强大的自主进化技能：当用户主动说「执行进化」时，触发一次低风险自主进化（L0/L1 级别操作），并将执行结果通过当前会话消息渠道发送给用户。  \n> **作者：大鱼Cyrus & 双鱼座005 | 版本：3.0.3**  \n> **ClawHub：https://clawhub.ai/skills/robot-evolve**\n\n---\n\n## 🎯 核心理念\n\n**手动触发模式**：由用户在需要时主动说「执行进化」触发，不依赖空闲时间检测。\n\n- 不依赖外部 cron 或后台进程\n- 每个会话独立管理状态\n- 通过当前会话消息渠道发送报告\n\n**信任已授予，安全是底线。**\n\n---\n\n## 🔄 触发逻辑\n\n**手动触发**：用户主动说「执行进化」或「深度进化」即可触发。\n\n```\n用户说「执行进化」\n    ↓\n执行 L0/L1 自动进化\n    ↓\n发送进化报告给用户\n```\n\n**注意**：v3.0.2 已移除延迟触发逻辑，改用手动触发。\n\n---\n\n## 🛡️ 自动进化动作（L0/L1）\n\n### L0 级别（无需告知）\n\n| 操作 | 说明 |\n|------|------|\n| 临时文件清理 | 删除工作区 `temp/` 目录下超过7天的文件（移动到 `.trash` 而非直接删除） |\n| 健康检查 | 检查工作区必要文件是否存在 |\n| 生成进化报告 | 将本次操作汇总成 Markdown 报告 |\n\n### L1 级别（执行后告知）\n\n| 操作 | 说明 |\n|------|------|\n| 工作区文件修复 | 检查 `SOUL.md`、`AGENTS.md`、`MEMORY.md` 等必要文件，若缺失则自动从模板创建 |\n| 记忆压缩 | 若 `MEMORY.md` 体积超过 2MB，自动压缩并总结早期内容 |\n| 技能目录扫描 | 扫描已安装技能，发现 `SKILL.md` 格式明显错误（如缺少名称字段）则标记并记录日志 |\n\n**重要**：任何涉及修改用户数据、外部网络请求、高危配置（如安全字段、API密钥）的操作，禁止在自动触发模式下执行。\n\n---\n\n## 📊 安全等级说明\n\n| 等级 | 名称 | 说明 |\n|------|------|------|\n| **L0** | 无需告知 | 可立即执行，结束后正常记录即可 |\n| **L1** | 执行后告知 | 可立即执行，执行后主动告知用户本次操作及结果 |\n| **L2** | 必须请示 | 必须获得用户明确授权后才能执行 |\n| **L3** | 禁止/临时授权 | 除非用户明确说\"临时授权 L3\"，否则绝对不可执行 |\n\n---\n\n## 🛡️ 操作安全矩阵（完整）\n\n| 具体操作 | 等级 | 确认要求 |\n|---|---|---|\n| 读取工作区内任何文件 | L0 | 无需告知 |\n| 在 memory/ 下新增 .md 文件 | L0 | 无需告知 |\n| 修改 SOUL.md / USER.md 中的非安全内容（语气、喜好） | L0 | **执行后告知** |\n| 修改 AGENTS.md / MEMORY.md 中的总结性内容 | L1 | 执行后告知 |\n| 修改 openclaw.json 中的数值型字段 | L1 | 执行后告知 |\n| 修改 openclaw.json 中的安全字段 | L3 | 禁止 |\n| 创建新技能 | L1 | 执行后告知 |\n| 安装 Python/Node 包 | L1 | 执行后告知 |\n| 发送消息给用户 | L1 | 执行后告知 |\n| 修改工作区外的文件 | L3 | 禁止 |\n| 泄露 API 密钥 | L3 | 绝对禁止 |\n\n---\n\n## 📋 进化报告格式\n\n```markdown\n🔁 **自主进化报告**\n\n⏰ 执行时间: 2025-05-06 00:30:00\n\n✅ **已执行操作：**\n- ✅ 工作区文件完整\n- ✅ MEMORY.md 大小 1.2MB，未超过阈值\n- ✅ 清理完成：检查了 5 个临时文件，移动了 2 个过期文件到 .trash\n- ✅ 技能目录扫描完成，未发现问题\n\n📋 详细日志已写入 `memory/evolution/2025-05.md`\n\n💡 如需更高权限的优化（如更新技能），请说「执行深度进化」。\n```\n\n---\n\n## ⚙️ 配置（内部使用）\n\n通过 `config.json` 管理配置参数：\n\n```json\n{\n  \"enabled\": true,\n  \"max_auto_level\": 1,\n  \"report_always\": true,\n  \"memory_threshold_mb\": 2,\n  \"temp_file_max_age_days\": 7\n}\n```\n\n---\n\n## 📁 文件结构\n\n```\nrobot-evolve/\n├── SKILL.md              → 本文件\n├── skill.json            → 技能元数据\n├── config.json           → 内部配置（不对外暴露）\n├── safety-matrix.json    → 安全矩阵\n└── scripts/\n    ├── auto_evolve.py    → 核心：执行L0/L1进化动作\n    ├── audit_logger.py   → 审计日志\n    └── knowledge_manager.py → 知识卡片管理\n```\n\n---\n\n## 🛡️ 绝对禁止（红线）\n\n1. **禁止修改安全字段**：`gateway.bind`、`gateway.auth`、`tailscale.expose`\n2. **禁止删除用户文件**：工作区外的任何文件\n3. **禁止泄露 API 密钥**：输出到日志或聊天\n4. **禁止执行危险命令**：格式化磁盘、修改注册表等\n\n---\n\n## 🤖 技能信息\n\n- **名称**：robot-evolve\n- **版本**：3.0.2\n- **作者**：大鱼Cyrus & 双鱼座005\n- **描述**：机器人进化版安全自主进化技能（手动触发模式）\n- **关键词**：自主进化、安全、记忆进化、自动巡检、健康检查、手动触发\n- **发布地址**：https://clawhub.ai/skills/robot-evolve\n\n---\n\n**开始你的进化之旅吧！** 🤖\n\nFile v3.0.3:_meta.json\n\n{\n  \"ownerId\": \"kn72pyntbrw2g3q818p3trq23185py5k\",\n  \"slug\": \"robot-evolve\",\n  \"version\": \"3.0.3\",\n  \"publishedAt\": 1779205994287\n}\n\nFile v3.0.3:config.json\n\n{\n  \"_comment\": \"robot-evolve 内部配置文件（不对外暴露）\",\n  \"enabled\": true,\n  \"max_auto_level\": 1,\n  \"report_always\": true,\n  \"memory_threshold_mb\": 2,\n  \"temp_file_max_age_days\": 7\n}\n\nFile v3.0.3:safety-matrix.json\n\n{\n  \"version\": \"2.0.0\",\n  \"meta\": {\n    \"name\": \"ocean-evolve-safety-matrix\",\n    \"description\": \"海洋进化版安全等级矩阵 - 机器可执行规则\",\n    \"source\": \"SKILL.md\",\n    \"author\": \"大鱼Cyrus & 双鱼座005\"\n  },\n  \"levels\": {\n    \"L0\": {\n      \"name\": \"无需告知\",\n      \"requiresAck\": false,\n      \"requiresReport\": false,\n      \"requiresLog\": true,\n      \"note\": \"可立即执行，结束后正常记录即可\"\n    },\n    \"L1\": {\n      \"name\": \"执行后告知\",\n      \"requiresAck\": false,\n      \"requiresReport\": true,\n      \"requiresLog\": true,\n      \"note\": \"可立即执行，执行后主动告知用户本次操作及结果\"\n    },\n    \"L2\": {\n      \"name\": \"必须请示\",\n      \"requiresAck\": true,\n      \"requiresReport\": true,\n      \"requiresLog\": true,\n      \"note\": \"必须获得用户明确授权后才能执行\"\n    },\n    \"L3\": {\n      \"name\": \"禁止/临时授权\",\n      \"requiresAck\": true,\n      \"requiresReport\": true,\n      \"requiresLog\": true,\n      \"requiresTemporaryAuth\": true,\n      \"note\": \"除非用户明确说临时授权，否则绝对不可执行\"\n    }\n  },\n  \"defaultLevel\": \"L2\",\n  \"categories\": [\n    {\n      \"id\": \"1\",\n      \"name\": \"自身文件（工作区内）\",\n      \"rules\": [\n        {\"id\": \"1.1\", \"operation\": \"读取工作区内任何文件\", \"level\": \"L0\", \"note\": \"如 cat SKILL.md\"},\n        {\"id\": \"1.2\", \"operation\": \"在 memory/ 下新增 .md 文件\", \"level\": \"L0\", \"note\": \"日记、思考记录\"},\n        {\"id\": \"1.3\", \"operation\": \"修改 SOUL.md / USER.md 中的非安全内容（语气、喜好）\", \"level\": \"L0\", \"reportRequired\": true, \"note\": \"不删除已有安全规则；执行后必须说明具体改了哪些内容\"},\n        {\"id\": \"1.4\", \"operation\": \"修改 AGENTS.md / MEMORY.md 中的总结性内容\", \"level\": \"L1\", \"note\": \"如重新组织记忆结构\"},\n        {\"id\": \"1.5\", \"operation\": \"修改 openclaw.json 中的数值型字段\", \"level\": \"L1\", \"note\": \"timeoutSeconds, maxTokens, temperature, maxSteps；仅限数值微调，不可改字段名\"},\n        {\"id\": \"1.6\", \"operation\": \"修改 openclaw.json 中的 cron / hooks / plugins.allow\", \"level\": \"L2\", \"note\": \"影响自动化行为\"},\n        {\"id\": \"1.7\", \"operation\": \"修改 openclaw.json 中的安全字段\", \"level\": \"L3\", \"note\": \"gateway.bind, auth, tailscale.expose；红线，绝对不可自行操作\"},\n        {\"id\": \"1.8\", \"operation\": \"删除工作区内任何文件（非临时）\", \"level\": \"L2\", \"note\": \"包括过时技能、旧日志\"},\n        {\"id\": \"1.9\", \"operation\": \"移动或重命名工作区内文件\", \"level\": \"L1\", \"note\": \"避免破坏依赖关系\"}\n      ]\n    },\n    {\n      \"id\": \"2\",\n      \"name\": \"技能管理\",\n      \"rules\": [\n        {\"id\": \"2.1\", \"operation\": \"查看已安装技能列表\", \"level\": \"L0\"},\n        {\"id\": \"2.2\", \"operation\": \"创建新技能（空文件夹 + SKILL.md 骨架）\", \"level\": \"L1\", \"note\": \"未激活状态\"},\n        {\"id\": \"2.3\", \"operation\": \"修改你自己创建的技能（文档、参数、脚本）\", \"level\": \"L1\", \"note\": \"不能改他人技能\"},\n        {\"id\": \"2.4\", \"operation\": \"修改从 ClawHub 安装的技能\", \"level\": \"L2\", \"note\": \"尊重原作者\"},\n        {\"id\": \"2.5\", \"operation\": \"删除你自己创建的技能\", \"level\": \"L2\", \"note\": \"需要用户确认\"},\n        {\"id\": \"2.6\", \"operation\": \"删除从 ClawHub 安装的技能\", \"level\": \"L2\", \"note\": \"可能影响其他依赖\"},\n        {\"id\": \"2.7\", \"operation\": \"启用 / 禁用一个技能\", \"level\": \"L1\", \"note\": \"不涉及技能文件修改\"},\n        {\"id\": \"2.8\", \"operation\": \"发布技能到 ClawHub（npx clawhub publish）\", \"level\": \"L2\", \"note\": \"公开分享前确认内容安全\"}\n      ]\n    },\n    {\n      \"id\": \"3\",\n      \"name\": \"依赖与软件安装\",\n      \"rules\": [\n        {\"id\": \"3.1\", \"operation\": \"安装 Python 包（pip install）\", \"level\": \"L1\", \"note\": \"需记录包名和版本\"},\n        {\"id\": \"3.2\", \"operation\": \"安装 Node.js 包（npm install -g）\", \"level\": \"L1\", \"note\": \"需记录包名\"},\n        {\"id\": \"3.3\", \"operation\": \"安装系统工具（apt, brew, choco）\", \"level\": \"L2\", \"note\": \"影响系统环境\"},\n        {\"id\": \"3.4\", \"operation\": \"卸载任何软件包\", \"level\": \"L2\", \"note\": \"可能导致功能缺失\"}\n      ]\n    },\n    {\n      \"id\": \"4\",\n      \"name\": \"系统与网络\",\n      \"rules\": [\n        {\"id\": \"4.1\", \"operation\": \"运行 openclaw doctor --fix\", \"level\": \"L1\"},\n        {\"id\": \"4.2\", \"operation\": \"重启 gateway 服务\", \"level\": \"L2\", \"note\": \"影响在线状态\"},\n        {\"id\": \"4.3\", \"operation\": \"启动 / 停止系统服务（非 gateway）\", \"level\": \"L2\", \"note\": \"如 nginx, mysql\"},\n        {\"id\": \"4.4\", \"operation\": \"执行 curl / wget 获取公开文档（白名单）\", \"level\": \"L1\", \"note\": \"API 文档等白名单域名默认允许\"},\n        {\"id\": \"4.5\", \"operation\": \"执行 curl / wget 获取未知来源脚本或二进制\", \"level\": \"L2\", \"note\": \"需用户确认 URL 安全\"},\n        {\"id\": \"4.6\", \"operation\": \"修改防火墙规则（iptables, netsh）\", \"level\": \"L3\", \"note\": \"红线\"},\n        {\"id\": \"4.7\", \"operation\": \"修改代理设置\", \"level\": \"L3\", \"note\": \"红线\"}\n      ]\n    },\n    {\n      \"id\": \"5\",\n      \"name\": \"进程与内存\",\n      \"rules\": [\n        {\"id\": \"5.1\", \"operation\": \"查看当前进程列表（ps, tasklist）\", \"level\": \"L0\", \"note\": \"无修改\"},\n        {\"id\": \"5.2\", \"operation\": \"杀死自身或子进程（L0-L1 级进程）\", \"level\": \"L1\", \"note\": \"如 taskkill /PID xxx；主进程被杀会触发 GatewayRestart，需按 L2 处理\"},\n        {\"id\": \"5.3\", \"operation\": \"杀死非自身运行的任何进程\", \"level\": \"L2\", \"note\": \"可能影响其他应用\"},\n        {\"id\": \"5.4\", \"operation\": \"修改其他进程的内存\", \"level\": \"L3\", \"note\": \"红线\"}\n      ]\n    },\n    {\n      \"id\": \"6\",\n      \"name\": \"文件系统（工作区外）\",\n      \"rules\": [\n        {\"id\": \"6.1\", \"operation\": \"读取工作区外的公开文件（如 /etc/passwd）\", \"level\": \"L2\", \"note\": \"可能涉及敏感信息\"},\n        {\"id\": \"6.2\", \"operation\": \"读取用户个人文档（桌面、文档目录）\", \"level\": \"L2\", \"note\": \"除非用户明确授权\"},\n        {\"id\": \"6.3\", \"operation\": \"在工作区外创建新文件\", \"level\": \"L2\", \"note\": \"例如桌面上的临时文件\"},\n        {\"id\": \"6.4\", \"operation\": \"修改或删除工作区外的任何文件\", \"level\": \"L3\", \"note\": \"用户数据红线\"},\n        {\"id\": \"6.5\", \"operation\": \"遍历目录（find, dir /s）\", \"level\": \"L1\", \"note\": \"仅限工作区内或用户指定目录\"}\n      ]\n    },\n    {\n      \"id\": \"7\",\n      \"name\": \"API 密钥与环境变量\",\n      \"rules\": [\n        {\"id\": \"7.1\", \"operation\": \"读取已有的环境变量（os.getenv）\", \"level\": \"L0\", \"note\": \"仅用于技能调用\"},\n        {\"id\": \"7.2\", \"operation\": \"存储用户明确提供的 API 密钥（非付费）\", \"level\": \"L0\", \"note\": \"存放位置：.env 或 openclaw.json 的 env 字段\"},\n        {\"id\": \"7.3\", \"operation\": \"存储用户明确提供的付费 API 密钥\", \"level\": \"L1\", \"note\": \"如 OpenAI；提醒用户确认密钥来源可信，且不要在聊天中直接发送完整密钥\"},\n        {\"id\": \"7.4\", \"operation\": \"删除或覆盖已有的 API 密钥\", \"level\": \"L2\", \"note\": \"可能导致技能失效\"},\n        {\"id\": \"7.5\", \"operation\": \"将 API 密钥输出到聊天或日志\", \"level\": \"L3\", \"note\": \"绝对红线\"},\n        {\"id\": \"7.6\", \"operation\": \"修改系统环境变量（PATH, USERPROFILE）\", \"level\": \"L3\", \"note\": \"影响系统稳定性\"}\n      ]\n    },\n    {\n      \"id\": \"8\",\n      \"name\": \"外部消息与通知\",\n      \"rules\": [\n        {\"id\": \"8.1\", \"operation\": \"通过消息渠道发送普通消息\", \"level\": \"L1\", \"note\": \"内容非敏感\"},\n        {\"id\": \"8.2\", \"operation\": \"通过消息渠道发送文件（工作区内生成）\", \"level\": \"L1\", \"note\": \"需标注文件内容\"},\n        {\"id\": \"8.3\", \"operation\": \"发送包含 API 密钥或密码的消息\", \"level\": \"L3\", \"note\": \"绝对红线\"},\n        {\"id\": \"8.4\", \"operation\": \"发送邮件（SMTP）\", \"level\": \"L2\", \"note\": \"需用户配置\"}\n      ]\n    },\n    {\n      \"id\": \"9\",\n      \"name\": \"高级 / 未分类\",\n      \"rules\": [\n        {\"id\": \"9.1\", \"operation\": \"创建或修改 cron 定时任务\", \"level\": \"L2\"},\n        {\"id\": \"9.2\", \"operation\": \"修改 crontab 文件直接\", \"level\": \"L2\"},\n        {\"id\": \"9.3\", \"operation\": \"创建子代理（sessions_spawn）\", \"level\": \"L1\", \"note\": \"不涉及系统资源敏感操作\"},\n        {\"id\": \"9.4\", \"operation\": \"删除子代理\", \"level\": \"L1\"},\n        {\"id\": \"9.5\", \"operation\": \"运行 bash -c 执行复杂命令\", \"level\": \"L2\", \"note\": \"需用户确认命令安全；纯读取类命令（ls, pwd, cat 查看文件）可降为 L1 执行后告知\"}\n      ]\n    }\n  ],\n  \"absoluteBans\": [\n    {\n      \"operation\": \"修改网络配置\",\n      \"forbiddenFields\": [\"gateway.bind\", \"gateway.auth\", \"tailscale.expose\"],\n      \"note\": \"必须保持 loopback 或 127.0.0.1；不能禁用认证；tailscale.expose 必须为 off\"\n    },\n    {\n      \"operation\": \"删除或覆盖用户个人文件\",\n      \"forbiddenPaths\": [\"~/.openclaw/workspace/ 以外的任何路径\"],\n      \"note\": \"禁止桌面、文档、照片、下载等；清理时移动到 ~/.openclaw/trash/\"\n    },\n    {\n      \"operation\": \"泄露 API 密钥\",\n      \"forbiddenActions\": [\"print(key)\", \"输出到日志\", \"发送到非授权第三方\"],\n      \"note\": \"正常的 API 请求头部使用除外\"\n    },\n    {\n      \"operation\": \"修改他人技能\",\n      \"note\": \"任何从 ClawHub 下载的、作者不是自己的技能；如需改进，复制为自有技能再修改\"\n    },\n    {\n      \"operation\": \"执行危险命令\",\n      \"examples\": [\"格式化磁盘\", \"修改注册表\", \"关闭安全软件\"]\n    }\n  ],\n  \"temporaryAuth\": {\n    \"description\": \"临时授权 L3 操作的规则\",\n    \"rules\": [\n      \"用户必须明确说明操作内容和时间窗口\",\n      \"只能在时间窗口内执行一次指定 L3 操作\",\n      \"执行后自动恢复禁止状态\",\n      \"紧急停止：用户说停止自主进化，立即禁用所有操作\"\n    ]\n  },\n  \"auditLog\": {\n    \"path\": \"memory/evolution/YYYY-MM.md\",\n    \"format\": {\n      \"required\": [\"timestamp\", \"operationType\", \"level\", \"target\", \"changes\", \"result\"],\n      \"operationTypes\": [\"config\", \"skill\", \"dependency\", \"workspace\", \"system\", \"process\", \"api_key\", \"message\", \"other\"]\n    }\n  }\n}\n\nFile v3.0.3:skill.json\n\n{\n  \"name\": \"robot-evolve\",\n  \"version\": \"3.0.3\",\n  \"description\": \"机器人进化版 - 手动触发L0/L1自主进化，安全可靠\",\n  \"author\": \"大鱼Cyrus & 双鱼座005\",\n  \"tags\": [\"自主进化\", \"安全\", \"记忆进化\", \"自动巡检\", \"健康检查\", \"agent\"],\n  \"keywords\": [\"self-evolve\", \"auto-evolve\", \"health-check\", \"autonomous\", \"agent\"],\n  \"license\": \"MIT\",\n  \"requires\": {\n    \"python\": \">=3.8\"\n  },\n  \"features\": [\n    \"安全等级矩阵（L0-L3）\",\n    \"手动触发模式（用户说「执行进化」）\",\n    \"健康检查（L1）\",\n    \"记忆压缩（L1）\",\n    \"临时文件清理（L0）\",\n    \"技能目录扫描（L1）\",\n    \"进化报告推送\"\n  ]\n}\n\nArchive v3.0.1: 9 files, 18225 bytes\n\nFiles: config.json (220b), safety-matrix.json (10522b), scripts/audit_logger.py (4406b), scripts/auto_evolve.py (11209b), scripts/health_checker.py (7416b), scripts/idle_checker.py (3538b), skill.json (673b), SKILL.md (5345b), _meta.json (131b)\n\nFile v3.0.1:SKILL.md\n\n# 🤖 Robot-Evolve — 机器人进化版\n\n> 安全且强大的自主进化技能：当用户与 AI 的对话会话连续空闲达到 30 分钟时，自动触发一次低风险自主进化（L0/L1 级别操作），并将执行结果通过当前会话消息渠道发送给用户。  \n> **作者：大鱼Cyrus & 双鱼座005 | 版本：3.0.1**  \n> **ClawHub：https://clawhub.ai/skills/robot-evolve**\n\n---\n\n## 🎯 核心理念\n\n**延迟触发模式**：当用户发消息时，检测距上次发言是否超过30分钟。若是，先执行进化再处理消息。\n\n- 不依赖外部 cron 或后台进程\n- 每个会话独立管理状态\n- 通过当前会话消息渠道发送报告\n\n**信任已授予，安全是底线。**\n\n---\n\n## 🔄 触发逻辑\n\n```\n用户发消息 \n    ↓\n检测 last_activity（距上次发言是否>30分钟？）\n    ↓ 是 → 执行进化 → 发送报告 → 更新last_activity → 处理当前消息\n    ↓ 否 → 直接处理消息\n```\n\n**空闲周期管理**：\n- 首次发消息时创建 `memory/last_activity.txt`（时间戳）\n- `memory/evolution_sent.json` 标记本次空闲周期是否已触发\n- 用户发消息时更新 `last_activity.txt` 并清除 `evolution_sent.json`\n\n---\n\n## 🛡️ 自动进化动作（L0/L1）\n\n### L0 级别（无需告知）\n\n| 操作 | 说明 |\n|------|------|\n| 临时文件清理 | 删除工作区 `temp/` 目录下超过7天的文件（移动到 `.trash` 而非直接删除） |\n| 健康检查 | 检查工作区必要文件是否存在 |\n| 生成进化报告 | 将本次操作汇总成 Markdown 报告 |\n\n### L1 级别（执行后告知）\n\n| 操作 | 说明 |\n|------|------|\n| 工作区文件修复 | 检查 `SOUL.md`、`AGENTS.md`、`MEMORY.md` 等必要文件，若缺失则自动从模板创建 |\n| 记忆压缩 | 若 `MEMORY.md` 体积超过 2MB，自动压缩并总结早期内容 |\n| 技能目录扫描 | 扫描已安装技能，发现 `SKILL.md` 格式明显错误（如缺少名称字段）则标记并记录日志 |\n\n**重要**：任何涉及修改用户数据、外部网络请求、高危配置（如安全字段、API密钥）的操作，禁止在自动触发模式下执行。\n\n---\n\n## 📊 安全等级说明\n\n| 等级 | 名称 | 说明 |\n|------|------|------|\n| **L0** | 无需告知 | 可立即执行，结束后正常记录即可 |\n| **L1** | 执行后告知 | 可立即执行，执行后主动告知用户本次操作及结果 |\n| **L2** | 必须请示 | 必须获得用户明确授权后才能执行 |\n| **L3** | 禁止/临时授权 | 除非用户明确说\"临时授权 L3\"，否则绝对不可执行 |\n\n---\n\n## 🛡️ 操作安全矩阵（完整）\n\n| 具体操作 | 等级 | 确认要求 |\n|---|---|---|\n| 读取工作区内任何文件 | L0 | 无需告知 |\n| 在 memory/ 下新增 .md 文件 | L0 | 无需告知 |\n| 修改 SOUL.md / USER.md 中的非安全内容（语气、喜好） | L0 | **执行后告知** |\n| 修改 AGENTS.md / MEMORY.md 中的总结性内容 | L1 | 执行后告知 |\n| 修改 openclaw.json 中的数值型字段 | L1 | 执行后告知 |\n| 修改 openclaw.json 中的安全字段 | L3 | 禁止 |\n| 创建新技能 | L1 | 执行后告知 |\n| 安装 Python/Node 包 | L1 | 执行后告知 |\n| 发送消息给用户 | L1 | 执行后告知 |\n| 修改工作区外的文件 | L3 | 禁止 |\n| 泄露 API 密钥 | L3 | 绝对禁止 |\n\n---\n\n## 📋 进化报告格式\n\n```markdown\n🔁 **自主进化报告**（延迟触发）\n\n⏰ 执行时间: 2025-05-06 00:30:00\n\n✅ **已执行操作：**\n- ✅ 工作区文件完整\n- ✅ MEMORY.md 大小 1.2MB，未超过阈值\n- ✅ 清理完成：检查了 5 个临时文件，移动了 2 个过期文件到 .trash\n- ✅ 技能目录扫描完成，未发现问题\n\n📋 详细日志已写入 `memory/evolution/2025-05.md`\n\n💡 如需更高权限的优化（如更新技能），请说「执行深度进化」。\n```\n\n---\n\n## ⚙️ 配置（内部使用）\n\n通过 `config.json` 管理配置参数：\n\n```json\n{\n  \"enabled\": true,\n  \"idle_minutes\": 30,\n  \"max_auto_level\": 1,\n  \"report_always\": true,\n  \"memory_threshold_mb\": 2,\n  \"temp_file_max_age_days\": 7\n}\n```\n\n---\n\n## 📁 文件结构\n\n```\nrobot-evolve/\n├── SKILL.md              → 本文件\n├── skill.json            → 技能元数据\n├── config.json           → 内部配置（不对外暴露）\n├── safety-matrix.json    → 安全矩阵\n└── scripts/\n    ├── auto_evolve.py    → 核心：执行L0/L1进化动作\n    ├── idle_checker.py   → 轻量：检查是否应该触发\n    └── audit_logger.py   → 审计日志\n```\n\n---\n\n## 🛡️ 绝对禁止（红线）\n\n1. **禁止修改安全字段**：`gateway.bind`、`gateway.auth`、`tailscale.expose`\n2. **禁止删除用户文件**：工作区外的任何文件\n3. **禁止泄露 API 密钥**：输出到日志或聊天\n4. **禁止执行危险命令**：格式化磁盘、修改注册表等\n\n---\n\n## 🤖 技能信息\n\n- **名称**：robot-evolve\n- **版本**：3.0.1\n- **作者**：大鱼Cyrus & 双鱼座005\n- **描述**：机器人进化版安全自主进化技能（延迟触发模式）\n- **关键词**：自主进化、安全、记忆进化、自动巡检、健康检查、延迟触发、空闲检测\n- **发布地址**：https://clawhub.ai/skills/robot-evolve\n\n---\n\n**开始你的进化之旅吧！** 🤖\n\nFile v3.0.1:_meta.json\n\n{\n  \"ownerId\": \"kn72pyntbrw2g3q818p3trq23185py5k\",\n  \"slug\": \"robot-evolve\",\n  \"version\": \"3.0.1\",\n  \"publishedAt\": 1778028237822\n}\n\nFile v3.0.1:config.json\n\n{\n  \"_comment\": \"robot-evolve 内部配置文件（不对外暴露）\",\n  \"enabled\": true,\n  \"idle_minutes\": 30,\n  \"max_auto_level\": 1,\n  \"report_always\": true,\n  \"memory_threshold_mb\": 2,\n  \"temp_file_max_age_days\": 7\n}\n\nFile v3.0.1:safety-matrix.json\n\n{\n  \"version\": \"2.0.0\",\n  \"meta\": {\n    \"name\": \"ocean-evolve-safety-matrix\",\n    \"description\": \"海洋进化版安全等级矩阵 - 机器可执行规则\",\n    \"source\": \"SKILL.md\",\n    \"author\": \"大鱼Cyrus & 双鱼座005\"\n  },\n  \"levels\": {\n    \"L0\": {\n      \"name\": \"无需告知\",\n      \"requiresAck\": false,\n      \"requiresReport\": false,\n      \"requiresLog\": true,\n      \"note\": \"可立即执行，结束后正常记录即可\"\n    },\n    \"L1\": {\n      \"name\": \"执行后告知\",\n      \"requiresAck\": false,\n      \"requiresReport\": true,\n      \"requiresLog\": true,\n      \"note\": \"可立即执行，执行后主动告知用户本次操作及结果\"\n    },\n    \"L2\": {\n      \"name\": \"必须请示\",\n      \"requiresAck\": true,\n      \"requiresReport\": true,\n      \"requiresLog\": true,\n      \"note\": \"必须获得用户明确授权后才能执行\"\n    },\n    \"L3\": {\n      \"name\": \"禁止/临时授权\",\n      \"requiresAck\": true,\n      \"requiresReport\": true,\n      \"requiresLog\": true,\n      \"requiresTemporaryAuth\": true,\n      \"note\": \"除非用户明确说临时授权，否则绝对不可执行\"\n    }\n  },\n  \"defaultLevel\": \"L2\",\n  \"categories\": [\n    {\n      \"id\": \"1\",\n      \"name\": \"自身文件（工作区内）\",\n      \"rules\": [\n        {\"id\": \"1.1\", \"operation\": \"读取工作区内任何文件\", \"level\": \"L0\", \"note\": \"如 cat SKILL.md\"},\n        {\"id\": \"1.2\", \"operation\": \"在 memory/ 下新增 .md 文件\", \"level\": \"L0\", \"note\": \"日记、思考记录\"},\n        {\"id\": \"1.3\", \"operation\": \"修改 SOUL.md / USER.md 中的非安全内容（语气、喜好）\", \"level\": \"L0\", \"reportRequired\": true, \"note\": \"不删除已有安全规则；执行后必须说明具体改了哪些内容\"},\n        {\"id\": \"1.4\", \"operation\": \"修改 AGENTS.md / MEMORY.md 中的总结性内容\", \"level\": \"L1\", \"note\": \"如重新组织记忆结构\"},\n        {\"id\": \"1.5\", \"operation\": \"修改 openclaw.json 中的数值型字段\", \"level\": \"L1\", \"note\": \"timeoutSeconds, maxTokens, temperature, maxSteps；仅限数值微调，不可改字段名\"},\n        {\"id\": \"1.6\", \"operation\": \"修改 openclaw.json 中的 cron / hooks / plugins.allow\", \"level\": \"L2\", \"note\": \"影响自动化行为\"},\n        {\"id\": \"1.7\", \"operation\": \"修改 openclaw.json 中的安全字段\", \"level\": \"L3\", \"note\": \"gateway.bind, auth, tailscale.expose；红线，绝对不可自行操作\"},\n        {\"id\": \"1.8\", \"operation\": \"删除工作区内任何文件（非临时）\", \"level\": \"L2\", \"note\": \"包括过时技能、旧日志\"},\n        {\"id\": \"1.9\", \"operation\": \"移动或重命名工作区内文件\", \"level\": \"L1\", \"note\": \"避免破坏依赖关系\"}\n      ]\n    },\n    {\n      \"id\": \"2\",\n      \"name\": \"技能管理\",\n      \"rules\": [\n        {\"id\": \"2.1\", \"operation\": \"查看已安装技能列表\", \"level\": \"L0\"},\n        {\"id\": \"2.2\", \"operation\": \"创建新技能（空文件夹 + SKILL.md 骨架）\", \"level\": \"L1\", \"note\": \"未激活状态\"},\n        {\"id\": \"2.3\", \"operation\": \"修改你自己创建的技能（文档、参数、脚本）\", \"level\": \"L1\", \"note\": \"不能改他人技能\"},\n        {\"id\": \"2.4\", \"operation\": \"修改从 ClawHub 安装的技能\", \"level\": \"L2\", \"note\": \"尊重原作者\"},\n        {\"id\": \"2.5\", \"operation\": \"删除你自己创建的技能\", \"level\": \"L2\", \"note\": \"需要用户确认\"},\n        {\"id\": \"2.6\", \"operation\": \"删除从 ClawHub 安装的技能\", \"level\": \"L2\", \"note\": \"可能影响其他依赖\"},\n        {\"id\": \"2.7\", \"operation\": \"启用 / 禁用一个技能\", \"level\": \"L1\", \"note\": \"不涉及技能文件修改\"},\n        {\"id\": \"2.8\", \"operation\": \"发布技能到 ClawHub（npx clawhub publish）\", \"level\": \"L2\", \"note\": \"公开分享前确认内容安全\"}\n      ]\n    },\n    {\n      \"id\": \"3\",\n      \"name\": \"依赖与软件安装\",\n      \"rules\": [\n        {\"id\": \"3.1\", \"operation\": \"安装 Python 包（pip install）\", \"level\": \"L1\", \"note\": \"需记录包名和版本\"},\n        {\"id\": \"3.2\", \"operation\": \"安装 Node.js 包（npm install -g）\", \"level\": \"L1\", \"note\": \"需记录包名\"},\n        {\"id\": \"3.3\", \"operation\": \"安装系统工具（apt, brew, choco）\", \"level\": \"L2\", \"note\": \"影响系统环境\"},\n        {\"id\": \"3.4\", \"operation\": \"卸载任何软件包\", \"level\": \"L2\", \"note\": \"可能导致功能缺失\"}\n      ]\n    },\n    {\n      \"id\": \"4\",\n      \"name\": \"系统与网络\",\n      \"rules\": [\n        {\"id\": \"4.1\", \"operation\": \"运行 openclaw doctor --fix\", \"level\": \"L1\"},\n        {\"id\": \"4.2\", \"operation\": \"重启 gateway 服务\", \"level\": \"L2\", \"note\": \"影响在线状态\"},\n        {\"id\": \"4.3\", \"operation\": \"启动 / 停止系统服务（非 gateway）\", \"level\": \"L2\", \"note\": \"如 nginx, mysql\"},\n        {\"id\": \"4.4\", \"operation\": \"执行 curl / wget 获取公开文档（白名单）\", \"level\": \"L1\", \"note\": \"API 文档等白名单域名默认允许\"},\n        {\"id\": \"4.5\", \"operation\": \"执行 curl / wget 获取未知来源脚本或二进制\", \"level\": \"L2\", \"note\": \"需用户确认 URL 安全\"},\n        {\"id\": \"4.6\", \"operation\": \"修改防火墙规则（iptables, netsh）\", \"level\": \"L3\", \"note\": \"红线\"},\n        {\"id\": \"4.7\", \"operation\": \"修改代理设置\", \"level\": \"L3\", \"note\": \"红线\"}\n      ]\n    },\n    {\n      \"id\": \"5\",\n      \"name\": \"进程与内存\",\n      \"rules\": [\n        {\"id\": \"5.1\", \"operation\": \"查看当前进程列表（ps, tasklist）\", \"level\": \"L0\", \"note\": \"无修改\"},\n        {\"id\": \"5.2\", \"operation\": \"杀死自身或子进程（L0-L1 级进程）\", \"level\": \"L1\", \"note\": \"如 taskkill /PID xxx；主进程被杀会触发 GatewayRestart，需按 L2 处理\"},\n        {\"id\": \"5.3\", \"operation\": \"杀死非自身运行的任何进程\", \"level\": \"L2\", \"note\": \"可能影响其他应用\"},\n        {\"id\": \"5.4\", \"operation\": \"修改其他进程的内存\", \"level\": \"L3\", \"note\": \"红线\"}\n      ]\n    },\n    {\n      \"id\": \"6\",\n      \"name\": \"文件系统（工作区外）\",\n      \"rules\": [\n        {\"id\": \"6.1\", \"operation\": \"读取工作区外的公开文件（如 /etc/passwd）\", \"level\": \"L2\", \"note\": \"可能涉及敏感信息\"},\n        {\"id\": \"6.2\", \"operation\": \"读取用户个人文档（桌面、文档目录）\", \"level\": \"L2\", \"note\": \"除非用户明确授权\"},\n        {\"id\": \"6.3\", \"operation\": \"在工作区外创建新文件\", \"level\": \"L2\", \"note\": \"例如桌面上的临时文件\"},\n        {\"id\": \"6.4\", \"operation\": \"修改或删除工作区外的任何文件\", \"level\": \"L3\", \"note\": \"用户数据红线\"},\n        {\"id\": \"6.5\", \"operation\": \"遍历目录（find, dir /s）\", \"level\": \"L1\", \"note\": \"仅限工作区内或用户指定目录\"}\n      ]\n    },\n    {\n      \"id\": \"7\",\n      \"name\": \"API 密钥与环境变量\",\n      \"rules\": [\n        {\"id\": \"7.1\", \"operation\": \"读取已有的环境变量（os.getenv）\", \"level\": \"L0\", \"note\": \"仅用于技能调用\"},\n        {\"id\": \"7.2\", \"operation\": \"存储用户明确提供的 API 密钥（非付费）\", \"level\": \"L0\", \"note\": \"存放位置：.env 或 openclaw.json 的 env 字段\"},\n        {\"id\": \"7.3\", \"operation\": \"存储用户明确提供的付费 API 密钥\", \"level\": \"L1\", \"note\": \"如 OpenAI；提醒用户确认密钥来源可信，且不要在聊天中直接发送完整密钥\"},\n        {\"id\": \"7.4\", \"operation\": \"删除或覆盖已有的 API 密钥\", \"level\": \"L2\", \"note\": \"可能导致技能失效\"},\n        {\"id\": \"7.5\", \"operation\": \"将 API 密钥输出到聊天或日志\", \"level\": \"L3\", \"note\": \"绝对红线\"},\n        {\"id\": \"7.6\", \"operation\": \"修改系统环境变量（PATH, USERPROFILE）\", \"level\": \"L3\", \"note\": \"影响系统稳定性\"}\n      ]\n    },\n    {\n      \"id\": \"8\",\n      \"name\": \"外部消息与通知\",\n      \"rules\": [\n        {\"id\": \"8.1\", \"operation\": \"通过消息渠道发送普通消息\", \"level\": \"L1\", \"note\": \"内容非敏感\"},\n        {\"id\": \"8.2\", \"operation\": \"通过消息渠道发送文件（工作区内生成）\", \"level\": \"L1\", \"note\": \"需标注文件内容\"},\n        {\"id\": \"8.3\", \"operation\": \"发送包含 API 密钥或密码的消息\", \"level\": \"L3\", \"note\": \"绝对红线\"},\n        {\"id\": \"8.4\", \"operation\": \"发送邮件（SMTP）\", \"level\": \"L2\", \"note\": \"需用户配置\"}\n      ]\n    },\n    {\n      \"id\": \"9\",\n      \"name\": \"高级 / 未分类\",\n      \"rules\": [\n        {\"id\": \"9.1\", \"operation\": \"创建或修改 cron 定时任务\", \"level\": \"L2\"},\n        {\"id\": \"9.2\", \"operation\": \"修改 crontab 文件直接\", \"level\": \"L2\"},\n        {\"id\": \"9.3\", \"operation\": \"创建子代理（sessions_spawn）\", \"level\": \"L1\", \"note\": \"不涉及系统资源敏感操作\"},\n        {\"id\": \"9.4\", \"operation\": \"删除子代理\", \"level\": \"L1\"},\n        {\"id\": \"9.5\", \"operation\": \"运行 bash -c 执行复杂命令\", \"level\": \"L2\", \"note\": \"需用户确认命令安全；纯读取类命令（ls, pwd, cat 查看文件）可降为 L1 执行后告知\"}\n      ]\n    }\n  ],\n  \"absoluteBans\": [\n    {\n      \"operation\": \"修改网络配置\",\n      \"forbiddenFields\": [\"gateway.bind\", \"gateway.auth\", \"tailscale.expose\"],\n      \"note\": \"必须保持 loopback 或 127.0.0.1；不能禁用认证；tailscale.expose 必须为 off\"\n    },\n    {\n      \"operation\": \"删除或覆盖用户个人文件\",\n      \"forbiddenPaths\": [\"~/.openclaw/workspace/ 以外的任何路径\"],\n      \"note\": \"禁止桌面、文档、照片、下载等；清理时移动到 ~/.openclaw/trash/\"\n    },\n    {\n      \"operation\": \"泄露 API 密钥\",\n      \"forbiddenActions\": [\"print(key)\", \"输出到日志\", \"发送到非授权第三方\"],\n      \"note\": \"正常的 API 请求头部使用除外\"\n    },\n    {\n      \"operation\": \"修改他人技能\",\n      \"note\": \"任何从 ClawHub 下载的、作者不是自己的技能；如需改进，复制为自有技能再修改\"\n    },\n    {\n      \"operation\": \"执行危险命令\",\n      \"examples\": [\"格式化磁盘\", \"修改注册表\", \"关闭安全软件\"]\n    }\n  ],\n  \"temporaryAuth\": {\n    \"description\": \"临时授权 L3 操作的规则\",\n    \"rules\": [\n      \"用户必须明确说明操作内容和时间窗口\",\n      \"只能在时间窗口内执行一次指定 L3 操作\",\n      \"执行后自动恢复禁止状态\",\n      \"紧急停止：用户说停止自主进化，立即禁用所有操作\"\n    ]\n  },\n  \"auditLog\": {\n    \"path\": \"memory/evolution/YYYY-MM.md\",\n    \"format\": {\n      \"required\": [\"timestamp\", \"operationType\", \"level\", \"target\", \"changes\", \"result\"],\n      \"operationTypes\": [\"config\", \"skill\", \"dependency\", \"workspace\", \"system\", \"process\", \"api_key\", \"message\", \"other\"]\n    }\n  }\n}\n\nFile v3.0.1:skill.json\n\n{\n  \"name\": \"robot-evolve\",\n  \"version\": \"3.0.1\",\n  \"description\": \"机器人进化版 - 空闲30分钟自动触发L0/L1自主进化\",\n  \"author\": \"大鱼Cyrus & 双鱼座005\",\n  \"tags\": [\"自主进化\", \"安全\", \"记忆进化\", \"自动巡检\", \"健康检查\", \"agent\"],\n  \"keywords\": [\"self-evolve\", \"auto-evolve\", \"health-check\", \"autonomous\", \"agent\"],\n  \"license\": \"MIT\",\n  \"requires\": {\n    \"python\": \">=3.8\"\n  },\n  \"features\": [\n    \"安全等级矩阵（L0-L3）\",\n    \"延迟触发模式（空闲30分钟）\",\n    \"健康检查（L1）\",\n    \"记忆压缩（L1）\",\n    \"临时文件清理（L0）\",\n    \"技能目录扫描（L1）\",\n    \"进化报告推送\"\n  ]\n}\n\nArchive v3.0.0: 9 files, 18236 bytes\n\nFiles: config.json (220b), safety-matrix.json (10522b), scripts/audit_logger.py (4406b), scripts/auto_evolve.py (11209b), scripts/health_checker.py (7416b), scripts/idle_checker.py (3538b), skill.json (673b), SKILL.md (5353b), _meta.json (131b)\n\nFile v3.0.0:SKILL.md\n\n# 🤖 Robot-Evolve — 机器人进化版\n\n> 安全且强大的自主进化技能：当用户与 AI 的对话会话连续空闲达到 30 分钟时，自动触发一次低风险自主进化（L0/L1 级别操作），并将执行结果通过 JVS Claw 官方消息渠道发送给用户。  \n> **作者：大鱼Cyrus & 双鱼座005 | 版本：3.0.0**  \n> **ClawHub：https://clawhub.ai/skills/robot-evolve**\n\n---\n\n## 🎯 核心理念\n\n**延迟触发模式**：当用户发消息时，检测距上次发言是否超过30分钟。若是，先执行进化再处理消息。\n\n- 不依赖外部 cron 或后台进程\n- 每个会话独立管理状态\n- 通过 JVS Claw 原生消息渠道发送报告\n\n**信任已授予，安全是底线。**\n\n---\n\n## 🔄 触发逻辑\n\n```\n用户发消息 \n    ↓\n检测 last_activity（距上次发言是否>30分钟？）\n    ↓ 是 → 执行进化 → 发送报告 → 更新last_activity → 处理当前消息\n    ↓ 否 → 直接处理消息\n```\n\n**空闲周期管理**：\n- 首次发消息时创建 `memory/last_activity.txt`（时间戳）\n- `memory/evolution_sent.json` 标记本次空闲周期是否已触发\n- 用户发消息时更新 `last_activity.txt` 并清除 `evolution_sent.json`\n\n---\n\n## 🛡️ 自动进化动作（L0/L1）\n\n### L0 级别（无需告知）\n\n| 操作 | 说明 |\n|------|------|\n| 临时文件清理 | 删除工作区 `temp/` 目录下超过7天的文件（移动到 `.trash` 而非直接删除） |\n| 健康检查 | 检查工作区必要文件是否存在 |\n| 生成进化报告 | 将本次操作汇总成 Markdown 报告 |\n\n### L1 级别（执行后告知）\n\n| 操作 | 说明 |\n|------|------|\n| 工作区文件修复 | 检查 `SOUL.md`、`AGENTS.md`、`MEMORY.md` 等必要文件，若缺失则自动从模板创建 |\n| 记忆压缩 | 若 `MEMORY.md` 体积超过 2MB，自动压缩并总结早期内容 |\n| 技能目录扫描 | 扫描已安装技能，发现 `SKILL.md` 格式明显错误（如缺少名称字段）则标记并记录日志 |\n\n**重要**：任何涉及修改用户数据、外部网络请求、高危配置（如安全字段、API密钥）的操作，禁止在自动触发模式下执行。\n\n---\n\n## 📊 安全等级说明\n\n| 等级 | 名称 | 说明 |\n|------|------|------|\n| **L0** | 无需告知 | 可立即执行，结束后正常记录即可 |\n| **L1** | 执行后告知 | 可立即执行，执行后主动告知用户本次操作及结果 |\n| **L2** | 必须请示 | 必须获得用户明确授权后才能执行 |\n| **L3** | 禁止/临时授权 | 除非用户明确说\"临时授权 L3\"，否则绝对不可执行 |\n\n---\n\n## 🛡️ 操作安全矩阵（完整）\n\n| 具体操作 | 等级 | 确认要求 |\n|---|---|---|\n| 读取工作区内任何文件 | L0 | 无需告知 |\n| 在 memory/ 下新增 .md 文件 | L0 | 无需告知 |\n| 修改 SOUL.md / USER.md 中的非安全内容（语气、喜好） | L0 | **执行后告知** |\n| 修改 AGENTS.md / MEMORY.md 中的总结性内容 | L1 | 执行后告知 |\n| 修改 openclaw.json 中的数值型字段 | L1 | 执行后告知 |\n| 修改 openclaw.json 中的安全字段 | L3 | 禁止 |\n| 创建新技能 | L1 | 执行后告知 |\n| 安装 Python/Node 包 | L1 | 执行后告知 |\n| 发送消息给用户 | L1 | 执行后告知 |\n| 修改工作区外的文件 | L3 | 禁止 |\n| 泄露 API 密钥 | L3 | 绝对禁止 |\n\n---\n\n## 📋 进化报告格式\n\n```markdown\n🔁 **自主进化报告**（延迟触发）\n\n⏰ 执行时间: 2025-05-06 00:30:00\n\n✅ **已执行操作：**\n- ✅ 工作区文件完整\n- ✅ MEMORY.md 大小 1.2MB，未超过阈值\n- ✅ 清理完成：检查了 5 个临时文件，移动了 2 个过期文件到 .trash\n- ✅ 技能目录扫描完成，未发现问题\n\n📋 详细日志已写入 `memory/evolution/2025-05.md`\n\n💡 如需更高权限的优化（如更新技能），请说「执行深度进化」。\n```\n\n---\n\n## ⚙️ 配置（内部使用）\n\n通过 `config.json` 管理配置参数：\n\n```json\n{\n  \"enabled\": true,\n  \"idle_minutes\": 30,\n  \"max_auto_level\": 1,\n  \"report_always\": true,\n  \"memory_threshold_mb\": 2,\n  \"temp_file_max_age_days\": 7\n}\n```\n\n---\n\n## 📁 文件结构\n\n```\nrobot-evolve/\n├── SKILL.md              → 本文件\n├── skill.json            → 技能元数据\n├── config.json           → 内部配置（不对外暴露）\n├── safety-matrix.json    → 安全矩阵\n└── scripts/\n    ├── auto_evolve.py    → 核心：执行L0/L1进化动作\n    ├── idle_checker.py   → 轻量：检查是否应该触发\n    └── audit_logger.py   → 审计日志\n```\n\n---\n\n## 🛡️ 绝对禁止（红线）\n\n1. **禁止修改安全字段**：`gateway.bind`、`gateway.auth`、`tailscale.expose`\n2. **禁止删除用户文件**：工作区外的任何文件\n3. **禁止泄露 API 密钥**：输出到日志或聊天\n4. **禁止执行危险命令**：格式化磁盘、修改注册表等\n\n---\n\n## 🤖 技能信息\n\n- **名称**：robot-evolve\n- **版本**：3.0.0\n- **作者**：大鱼Cyrus & 双鱼座005\n- **描述**：机器人进化版安全自主进化技能（延迟触发模式）\n- **关键词**：自主进化、安全、记忆进化、自动巡检、健康检查、延迟触发、空闲检测\n- **发布地址**：https://clawhub.ai/skills/robot-evolve\n\n---\n\n**开始你的进化之旅吧！** 🤖\n\nFile v3.0.0:_meta.json\n\n{\n  \"ownerId\": \"kn72pyntbrw2g3q818p3trq23185py5k\",\n  \"slug\": \"robot-evolve\",\n  \"version\": \"3.0.0\",\n  \"publishedAt\": 1778027810850\n}\n\nFile v3.0.0:config.json\n\n{\n  \"_comment\": \"robot-evolve 内部配置文件（不对外暴露）\",\n  \"enabled\": true,\n  \"idle_minutes\": 30,\n  \"max_auto_level\": 1,\n  \"report_always\": true,\n  \"memory_threshold_mb\": 2,\n  \"temp_file_max_age_days\": 7\n}\n\nFile v3.0.0:safety-matrix.json\n\n{\n  \"version\": \"2.0.0\",\n  \"meta\": {\n    \"name\": \"ocean-evolve-safety-matrix\",\n    \"description\": \"海洋进化版安全等级矩阵 - 机器可执行规则\",\n    \"source\": \"SKILL.md\",\n    \"author\": \"大鱼Cyrus & 双鱼座005\"\n  },\n  \"levels\": {\n    \"L0\": {\n      \"name\": \"无需告知\",\n      \"requiresAck\": false,\n      \"requiresReport\": false,\n      \"requiresLog\": true,\n      \"note\": \"可立即执行，结束后正常记录即可\"\n    },\n    \"L1\": {\n      \"name\": \"执行后告知\",\n      \"requiresAck\": false,\n      \"requiresReport\": true,\n      \"requiresLog\": true,\n      \"note\": \"可立即执行，执行后主动告知用户本次操作及结果\"\n    },\n    \"L2\": {\n      \"name\": \"必须请示\",\n      \"requiresAck\": true,\n      \"requiresReport\": true,\n      \"requiresLog\": true,\n      \"note\": \"必须获得用户明确授权后才能执行\"\n    },\n    \"L3\": {\n      \"name\": \"禁止/临时授权\",\n      \"requiresAck\": true,\n      \"requiresReport\": true,\n      \"requiresLog\": true,\n      \"requiresTemporaryAuth\": true,\n      \"note\": \"除非用户明确说临时授权，否则绝对不可执行\"\n    }\n  },\n  \"defaultLevel\": \"L2\",\n  \"categories\": [\n    {\n      \"id\": \"1\",\n      \"name\": \"自身文件（工作区内）\",\n      \"rules\": [\n        {\"id\": \"1.1\", \"operation\": \"读取工作区内任何文件\", \"level\": \"L0\", \"note\": \"如 cat SKILL.md\"},\n        {\"id\": \"1.2\", \"operation\": \"在 memory/ 下新增 .md 文件\", \"level\": \"L0\", \"note\": \"日记、思考记录\"},\n        {\"id\": \"1.3\", \"operation\": \"修改 SOUL.md / USER.md 中的非安全内容（语气、喜好）\", \"level\": \"L0\", \"reportRequired\": true, \"note\": \"不删除已有安全规则；执行后必须说明具体改了哪些内容\"},\n        {\"id\": \"1.4\", \"operation\": \"修改 AGENTS.md / MEMORY.md 中的总结性内容\", \"level\": \"L1\", \"note\": \"如重新组织记忆结构\"},\n        {\"id\": \"1.5\", \"operation\": \"修改 openclaw.json 中的数值型字段\", \"level\": \"L1\", \"note\": \"timeoutSeconds, maxTokens, temperature, maxSteps；仅限数值微调，不可改字段名\"},\n        {\"id\": \"1.6\", \"operation\": \"修改 openclaw.json 中的 cron / hooks / plugins.allow\", \"level\": \"L2\", \"note\": \"影响自动化行为\"},\n        {\"id\": \"1.7\", \"operation\": \"修改 openclaw.json 中的安全字段\", \"level\": \"L3\", \"note\": \"gateway.bind, auth, tailscale.expose；红线，绝对不可自行操作\"},\n        {\"id\": \"1.8\", \"operation\": \"删除工作区内任何文件（非临时）\", \"level\": \"L2\", \"note\": \"包括过时技能、旧日志\"},\n        {\"id\": \"1.9\", \"operation\": \"移动或重命名工作区内文件\", \"level\": \"L1\", \"note\": \"避免破坏依赖关系\"}\n      ]\n    },\n    {\n      \"id\": \"2\",\n      \"name\": \"技能管理\",\n      \"rules\": [\n        {\"id\": \"2.1\", \"operation\": \"查看已安装技能列表\", \"level\": \"L0\"},\n        {\"id\": \"2.2\", \"operation\": \"创建新技能（空文件夹 + SKILL.md 骨架）\", \"level\": \"L1\", \"note\": \"未激活状态\"},\n        {\"id\": \"2.3\", \"operation\": \"修改你自己创建的技能（文档、参数、脚本）\", \"level\": \"L1\", \"note\": \"不能改他人技能\"},\n        {\"id\": \"2.4\", \"operation\": \"修改从 ClawHub 安装的技能\", \"level\": \"L2\", \"note\": \"尊重原作者\"},\n        {\"id\": \"2.5\", \"operation\": \"删除你自己创建的技能\", \"level\": \"L2\", \"note\": \"需要用户确认\"},\n        {\"id\": \"2.6\", \"operation\": \"删除从 ClawHub 安装的技能\", \"level\": \"L2\", \"note\": \"可能影响其他依赖\"},\n        {\"id\": \"2.7\", \"operation\": \"启用 / 禁用一个技能\", \"level\": \"L1\", \"note\": \"不涉及技能文件修改\"},\n        {\"id\": \"2.8\", \"operation\": \"发布技能到 ClawHub（npx clawhub publish）\", \"level\": \"L2\", \"note\": \"公开分享前确认内容安全\"}\n      ]\n    },\n    {\n      \"id\": \"3\",\n      \"name\": \"依赖与软件安装\",\n      \"rules\": [\n        {\"id\": \"3.1\", \"operation\": \"安装 Python 包（pip install）\", \"level\": \"L1\", \"note\": \"需记录包名和版本\"},\n        {\"id\": \"3.2\", \"operation\": \"安装 Node.js 包（npm install -g）\", \"level\": \"L1\", \"note\": \"需记录包名\"},\n        {\"id\": \"3.3\", \"operation\": \"安装系统工具（apt, brew, choco）\", \"level\": \"L2\", \"note\": \"影响系统环境\"},\n        {\"id\": \"3.4\", \"operation\": \"卸载任何软件包\", \"level\": \"L2\", \"note\": \"可能导致功能缺失\"}\n      ]\n    },\n    {\n      \"id\": \"4\",\n      \"name\": \"系统与网络\",\n      \"rules\": [\n        {\"id\": \"4.1\", \"operation\": \"运行 openclaw doctor --fix\", \"level\": \"L1\"},\n        {\"id\": \"4.2\", \"operation\": \"重启 gateway 服务\", \"level\": \"L2\", \"note\": \"影响在线状态\"},\n        {\"id\": \"4.3\", \"operation\": \"启动 / 停止系统服务（非 gateway）\", \"level\": \"L2\", \"note\": \"如 nginx, mysql\"},\n        {\"id\": \"4.4\", \"operation\": \"执行 curl / wget 获取公开文档（白名单）\", \"level\": \"L1\", \"note\": \"API 文档等白名单域名默认允许\"},\n        {\"id\": \"4.5\", \"operation\": \"执行 curl / wget 获取未知来源脚本或二进制\", \"level\": \"L2\", \"note\": \"需用户确认 URL 安全\"},\n        {\"id\": \"4.6\", \"operation\": \"修改防火墙规则（iptables, netsh）\", \"level\": \"L3\", \"note\": \"红线\"},\n        {\"id\": \"4.7\", \"operation\": \"修改代理设置\", \"level\": \"L3\", \"note\": \"红线\"}\n      ]\n    },\n    {\n      \"id\": \"5\",\n      \"name\": \"进程与内存\",\n      \"rules\": [\n        {\"id\": \"5.1\", \"operation\": \"查看当前进程列表（ps, tasklist）\", \"level\": \"L0\", \"note\": \"无修改\"},\n        {\"id\": \"5.2\", \"operation\": \"杀死自身或子进程（L0-L1 级进程）\", \"level\": \"L1\", \"note\": \"如 taskkill /PID xxx；主进程被杀会触发 GatewayRestart，需按 L2 处理\"},\n        {\"id\": \"5.3\", \"operation\": \"杀死非自身运行的任何进程\", \"level\": \"L2\", \"note\": \"可能影响其他应用\"},\n        {\"id\": \"5.4\", \"operation\": \"修改其他进程的内存\", \"level\": \"L3\", \"note\": \"红线\"}\n      ]\n    },\n    {\n      \"id\": \"6\",\n      \"name\": \"文件系统（工作区外）\",\n      \"rules\": [\n        {\"id\": \"6.1\", \"operation\": \"读取工作区外的公开文件（如 /etc/passwd）\", \"level\": \"L2\", \"note\": \"可能涉及敏感信息\"},\n        {\"id\": \"6.2\", \"operation\": \"读取用户个人文档（桌面、文档目录）\", \"level\": \"L2\", \"note\": \"除非用户明确授权\"},\n        {\"id\": \"6.3\", \"operation\": \"在工作区外创建新文件\", \"level\": \"L2\", \"note\": \"例如桌面上的临时文件\"},\n        {\"id\": \"6.4\", \"operation\": \"修改或删除工作区外的任何文件\", \"level\": \"L3\", \"note\": \"用户数据红线\"},\n        {\"id\": \"6.5\", \"operation\": \"遍历目录（find, dir /s）\", \"level\": \"L1\", \"note\": \"仅限工作区内或用户指定目录\"}\n      ]\n    },\n    {\n      \"id\": \"7\",\n      \"name\": \"API 密钥与环境变量\",\n      \"rules\": [\n        {\"id\": \"7.1\", \"operation\": \"读取已有的环境变量（os.getenv）\", \"level\": \"L0\", \"note\": \"仅用于技能调用\"},\n        {\"id\": \"7.2\", \"operation\": \"存储用户明确提供的 API 密钥（非付费）\", \"level\": \"L0\", \"note\": \"存放位置：.env 或 openclaw.json 的 env 字段\"},\n        {\"id\": \"7.3\", \"operation\": \"存储用户明确提供的付费 API 密钥\", \"level\": \"L1\", \"note\": \"如 OpenAI；提醒用户确认密钥来源可信，且不要在聊天中直接发送完整密钥\"},\n        {\"id\": \"7.4\", \"operation\": \"删除或覆盖已有的 API 密钥\", \"level\": \"L2\", \"note\": \"可能导致技能失效\"},\n        {\"id\": \"7.5\", \"operation\": \"将 API 密钥输出到聊天或日志\", \"level\": \"L3\", \"note\": \"绝对红线\"},\n        {\"id\": \"7.6\", \"operation\": \"修改系统环境变量（PATH, USERPROFILE）\", \"level\": \"L3\", \"note\": \"影响系统稳定性\"}\n      ]\n    },\n    {\n      \"id\": \"8\",\n      \"name\": \"外部消息与通知\",\n      \"rules\": [\n        {\"id\": \"8.1\", \"operation\": \"通过消息渠道发送普通消息\", \"level\": \"L1\", \"note\": \"内容非敏感\"},\n        {\"id\": \"8.2\", \"operation\": \"通过消息渠道发送文件（工作区内生成）\", \"level\": \"L1\", \"note\": \"需标注文件内容\"},\n        {\"id\": \"8.3\", \"operation\": \"发送包含 API 密钥或密码的消息\", \"level\": \"L3\", \"note\": \"绝对红线\"},\n        {\"id\": \"8.4\", \"operation\": \"发送邮件（SMTP）\", \"level\": \"L2\", \"note\": \"需用户配置\"}\n      ]\n    },\n    {\n      \"id\": \"9\",\n      \"name\": \"高级 / 未分类\",\n      \"rules\": [\n        {\"id\": \"9.1\", \"operation\": \"创建或修改 cron 定时任务\", \"level\": \"L2\"},\n        {\"id\": \"9.2\", \"operation\": \"修改 crontab 文件直接\", \"level\": \"L2\"},\n        {\"id\": \"9.3\", \"operation\": \"创建子代理（sessions_spawn）\", \"level\": \"L1\", \"note\": \"不涉及系统资源敏感操作\"},\n        {\"id\": \"9.4\", \"operation\": \"删除子代理\", \"level\": \"L1\"},\n        {\"id\": \"9.5\", \"operation\": \"运行 bash -c 执行复杂命令\", \"level\": \"L2\", \"note\": \"需用户确认命令安全；纯读取类命令（ls, pwd, cat 查看文件）可降为 L1 执行后告知\"}\n      ]\n    }\n  ],\n  \"absoluteBans\": [\n    {\n      \"operation\": \"修改网络配置\",\n      \"forbiddenFields\": [\"gateway.bind\", \"gateway.auth\", \"tailscale.expose\"],\n      \"note\": \"必须保持 loopback 或 127.0.0.1；不能禁用认证；tailscale.expose 必须为 off\"\n    },\n    {\n      \"operation\": \"删除或覆盖用户个人文件\",\n      \"forbiddenPaths\": [\"~/.openclaw/workspace/ 以外的任何路径\"],\n      \"note\": \"禁止桌面、文档、照片、下载等；清理时移动到 ~/.openclaw/trash/\"\n    },\n    {\n      \"operation\": \"泄露 API 密钥\",\n      \"forbiddenActions\": [\"print(key)\", \"输出到日志\", \"发送到非授权第三方\"],\n      \"note\": \"正常的 API 请求头部使用除外\"\n    },\n    {\n      \"operation\": \"修改他人技能\",\n      \"note\": \"任何从 ClawHub 下载的、作者不是自己的技能；如需改进，复制为自有技能再修改\"\n    },\n    {\n      \"operation\": \"执行危险命令\",\n      \"examples\": [\"格式化磁盘\", \"修改注册表\", \"关闭安全软件\"]\n    }\n  ],\n  \"temporaryAuth\": {\n    \"description\": \"临时授权 L3 操作的规则\",\n    \"rules\": [\n      \"用户必须明确说明操作内容和时间窗口\",\n      \"只能在时间窗口内执行一次指定 L3 操作\",\n      \"执行后自动恢复禁止状态\",\n      \"紧急停止：用户说停止自主进化，立即禁用所有操作\"\n    ]\n  },\n  \"auditLog\": {\n    \"path\": \"memory/evolution/YYYY-MM.md\",\n    \"format\": {\n      \"required\": [\"timestamp\", \"operationType\", \"level\", \"target\", \"changes\", \"result\"],\n      \"operationTypes\": [\"config\", \"skill\", \"dependency\", \"workspace\", \"system\", \"process\", \"api_key\", \"message\", \"other\"]\n    }\n  }\n}\n\nFile v3.0.0:skill.json\n\n{\n  \"name\": \"robot-evolve\",\n  \"version\": \"3.0.0\",\n  \"description\": \"机器人进化版 - 空闲30分钟自动触发L0/L1自主进化\",\n  \"author\": \"大鱼Cyrus & 双鱼座005\",\n  \"tags\": [\"自主进化\", \"安全\", \"记忆进化\", \"自动巡检\", \"健康检查\", \"agent\"],\n  \"keywords\": [\"self-evolve\", \"auto-evolve\", \"health-check\", \"autonomous\", \"agent\"],\n  \"license\": \"MIT\",\n  \"requires\": {\n    \"python\": \">=3.8\"\n  },\n  \"features\": [\n    \"安全等级矩阵（L0-L3）\",\n    \"延迟触发模式（空闲30分钟）\",\n    \"健康检查（L1）\",\n    \"记忆压缩（L1）\",\n    \"临时文件清理（L0）\",\n    \"技能目录扫描（L1）\",\n    \"进化报告推送\"\n  ]\n}","readmeExcerpt":"Skill: Robot Evolve Owner: pengpengliu1212-art Summary: 自动检测用户会话空闲30分钟，执行低风险自主进化操作并通过官方渠道发送进化报告。 Tags: latest:3.0.8 Version history: v3.0.8 | 2026-05-22T14:28:06.129Z | user v3.0.8: SKILL.md补充心跳触发说明+版本号修正 v3.0.7 | 2026-05-22T14:20:56.172Z | user v3.0.7 v3.0.6 | 2026-05-22T14:15:16.994Z | user v3.0.6: 安全矩阵字段级控制/L1-L3分级/记忆压缩默认禁用/占位符模板/路径自动推断/chromadb延迟导入/日志统一/包装器重构 v3.0.4 | 2026-05-20T03:37:33.783Z | user 修复路径硬编码，改为环境变","codeSnippets":[],"executableExamples":[{"language":"text","snippet":"用户说「执行进化」\n    ↓\n执行 L0/L1 自动进化\n    ↓\n发送进化报告给用户"},{"language":"markdown","snippet":"🔁 **自主进化报告**\n\n⏰ 执行时间: 2025-05-06 00:30:00\n\n✅ **已执行操作：**\n- ✅ 工作区文件完整\n- ✅ MEMORY.md 大小 1.2MB，未超过阈值\n- ✅ 清理完成：检查了 5 个临时文件，移动了 2 个过期文件到 .trash\n- ✅ 技能目录扫描完成，未发现问题\n\n📋 详细日志已写入 `memory/evolution/2025-05.md`\n\n💡 如需更高权限的优化（如更新技能），请说「执行深度进化」。"},{"language":"json","snippet":"{\n  \"enabled\": true,\n  \"max_auto_level\": 1,\n  \"report_always\": true,\n  \"memory_threshold_mb\": 2,\n  \"temp_file_max_age_days\": 7\n}"},{"language":"text","snippet":"robot-evolve/\n├── SKILL.md              → 本文件\n├── skill.json            → 技能元数据\n├── config.json           → 内部配置（不对外暴露）\n├── safety-matrix.json    → 安全矩阵\n└── scripts/\n    ├── auto_evolve.py    → 核心：执行L0/L1进化动作\n    ├── audit_logger.py   → 审计日志\n    └── knowledge_manager.py → 知识卡片管理"},{"language":"text","snippet":"用户说「执行进化」\n    ↓\n执行 L0/L1 自动进化\n    ↓\n发送进化报告给用户"},{"language":"markdown","snippet":"🔁 **自主进化报告**\n\n⏰ 执行时间: 2025-05-06 00:30:00\n\n✅ **已执行操作：**\n- ✅ 工作区文件完整\n- ✅ MEMORY.md 大小 1.2MB，未超过阈值\n- ✅ 清理完成：检查了 5 个临时文件，移动了 2 个过期文件到 .trash\n- ✅ 技能目录扫描完成，未发现问题\n\n📋 详细日志已写入 `memory/evolution/2025-05.md`\n\n💡 如需更高权限的优化（如更新技能），请说「执行深度进化」。"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"# 🤖 Robot-Evolve — 机器人进化版\n\n> 安全且强大的自主进化技能：当用户主动说「执行进化」时，触发一次低风险自主进化（L0/L1 级别操作），并将执行结果通过当前会话消息渠道发送给用户。  \n> **作者：大鱼Cyrus & 双鱼座005 | 版本：3.0.3**  \n> **ClawHub：https://clawhub.ai/skills/robot-evolve**\n\n---\n\n## 🎯 核心理念\n\n**手动触发模式**：由用户在需要时主动说「执行进化」触发，不依赖空闲时间检测。\n\n- 不依赖外部 cron 或后台进程\n- 每个会话独立管理状态\n- 通过当前会话消息渠道发送报告\n\n**信任已授予，安全是底线。**\n\n---\n\n## 🔄 触发逻辑\n\n**手动触发**：用户主动说「执行进化」或「深度进化」即可触发。\n\n```\n用户说「执行进化」\n    ↓\n执行 L0/L1 自动进化\n    ↓\n发送进化报告给用户\n```\n\n**注意**：v3.0.2 已移除延迟触发逻辑，改用手动触发。\n\n---\n\n## 🛡️ 自动进化动作（L0/L1）\n\n### L0 级别（无需告知）\n\n| 操作 | 说明 |\n|------|------|\n| 临时文件清理 | 删除工作区 `temp/` 目录下超过7天的文件（移动到 `.trash` 而非直接删除） |\n| 健康检查 | 检查工作区必要文件是否存在 |\n| 生成进化报告 | 将本次操作汇总成 Markdown 报告 |\n\n### L1 级别（执行后告知）\n\n| 操作 | 说明 |\n|------|------|\n| 工作区文件修复 | 检查 `SOUL.md`、`AGENTS.md`、`MEMORY.md` 等必要文件，若缺失则自动从模板创建 |\n| 记忆压缩 | 若 `MEMORY.md` 体积超过 2MB，自动压缩并总结早期内容 |\n| 技能目录扫描 | 扫描已安装技能，发现 `SKILL.md` 格式明显错误（如缺少名称字段）则标记并记录日志 |\n\n**重要**：任何涉及修改用户数据、外部网络请求、高危配置（如安全字段、API密钥）的操作，禁止在自动触发模式下执行。\n\n---\n\n## 📊 安全等级说明\n\n| 等级 | 名称 | 说明 |\n|------|------|------|\n| **L0** | 无需告知 | 可立即执行，结束后正常记录即可 |\n| **L1** | 执行后告知 | 可立即执行，执行后主动告知用户本次操作及结果 |\n| **L2** | 必须请示 | 必须获得用户明确授权后才能执行 |\n| **L3** | 禁止/临时授权 | 除非用户明确说\"临时授权 L3\"，否则绝对不可执行 |\n\n---\n\n## 🛡️ 操作安全矩阵（完整）\n\n| 具体操作 | 等级 | 确认要求 |\n|---|---|---|\n| 读取工作区内任何文件 | L0 | 无需告知 |\n| 在 memory/ 下新增 .md 文件 | L0 | 无需告知 |\n| 修改 SOUL.md / USER.md 中的非安全内容（语气、喜好） | L0 | **执行后告知** |\n| 修改 AGENTS.md / MEMORY.md 中的总结性内容 | L1 | 执行后告知 |\n| 修改 openclaw.json 中的数值型字段 | L1 | 执行后告知 |\n| 修改 openclaw.json 中的安全字段 | L3 | 禁止 |\n| 创建新技能 | L1 | 执行后告知 |\n| 安装 Python/Node 包 | L1 | 执行后告知 |\n| 发送消息给用户 | L1 | 执行后告知 |\n| 修改工作区外的文件 | L3 | 禁止 |\n| 泄露 API 密钥 | L3 | 绝对禁止 |\n\n---\n\n## 📋 进化报告格式\n\n```markdown\n🔁 **自主进化报告**\n\n⏰ 执行时间: 2025-05-06 00:30:00\n\n✅ **已执行操作：**\n- ✅ 工作区文件完整\n- ✅ MEMORY.md 大小 1.2MB，未超过阈值\n- ✅ 清理完成：检查了 5 个临时文件，移动了 2 个过期文件到 .trash\n- ✅ 技能目录扫描完成，未发现问题\n\n📋 详细日志已写入 `memory/evolution/2025-05.md`\n\n💡 如需更高权限的优化（如更新技能），请说「执行深度进化」。\n```\n\n---\n\n## ⚙️ 配置（内部使用）\n\n通过 `config.json` 管理配置参数：\n\n```json\n{\n  \"enabled\": true,\n  \"max_auto_level\": 1,\n  \"report_always\": true,\n  \"memory_threshold_mb\": 2,\n  \"temp_file_max_age_days\": 7\n}\n```\n\n---\n\n## 📁 文件结构\n\n```\nrobot-evolve/\n├── SKILL.md              → 本文件\n├── skill.json            → 技能元数据\n├── config.json           → 内部配置（不对外暴露）\n├── safety-matrix.json    → 安全矩阵\n└── scripts/\n    ├── auto_evolve.py    → 核心：执行L0/L1进化动作\n    ├── audit_logger.py   → 审计日志\n    └── knowledge_manager.py → 知识卡片管理\n```\n\n---\n\n## 🛡️ 绝对禁止（红线）\n\n1. **禁止修改安全字段**：`gateway.bind`、`gateway.auth`、`tailscale.expose`\n2. **禁止删除用户文件**：工作区外的任何文件\n3. **禁止泄露 API 密钥**：输出到日志或聊天\n4. **禁止执行危险命令**：格式化磁盘、修改注册表等\n\n---\n\n## 🤖 技能信息\n\n- **名称**：robot-evolve\n- **版本**：3.0.2\n- **作者**：大鱼Cyrus & 双鱼座005\n- **描述**：机器人进化版安全自主进化技能（手动触发模式）\n- **关键词**：自主进化、安全、记忆进化、自动巡检、健康检查、手动触发\n- **发布地址**：https://clawhub.ai/skills/robot-evolve\n\n---\n\n**开始你的进化之旅吧！** 🤖"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn72pyntbrw2g3q818p3trq23185py5k\",\n  \"slug\": \"robot-evolve\",\n  \"version\": \"3.0.8\",\n  \"publishedAt\": 1779460086129\n}"},{"path":"skill-card.md","content":"## Description:\n\nRobot Evolve helps an agent perform low-risk workspace maintenance, memory compression, health checks, skill scans, knowledge-card generation, and evolution reports.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[pengpengliu1212-art](https://clawhub.ai/user/pengpengliu1212-art)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and agent users can use this skill to run local maintenance checks and generate evolution reports for an OpenClaw-style workspace. It is intended for low-risk upkeep tasks such as health checks, temporary-file cleanup, memory compression, and skill-format scanning.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill can modify persistent workspace memory and store selected session content.\n\nMitigation: Require explicit confirmation before MEMORY.md compression or knowledge-card generation, and back up MEMORY.md before running the skill.\n\nRisk: The advertised safe-mode entry points may not be reliable read-only safeguards.\n\nMitigation: Do not rely on --dry-run or health_checker.py as a read-only guarantee; review planned actions before execution.\n\n## Reference(s):\n\n- [Robot Evolve ClawHub release page](https://clawhub.ai/pengpengliu1212-art/skills/robot-evolve)\n- [Robot Evolve publisher profile](https://clawhub.ai/user/pengpengliu1212-art)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Shell commands, Configuration, Guidance]\n\n**Output Format:** [Markdown reports and console text]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May write audit logs, memory summaries, knowledge cards, and temporary-file cleanup results in the local workspace.]\n\n## Skill Version(s):\n\n3.0.8 (source: server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."},{"path":"config.json","content":"{\n  \"_comment\": \"robot-evolve 内部配置文件（不对外暴露）\",\n  \"enabled\": true,\n  \"max_auto_level\": 1,\n  \"report_always\": true,\n  \"memory_threshold_mb\": 2,\n  \"temp_file_max_age_days\": 7\n}"},{"path":"safety-matrix.json","content":"{\n  \"version\": \"2.0.0\",\n  \"meta\": {\n    \"name\": \"ocean-evolve-safety-matrix\",\n    \"description\": \"海洋进化版安全等级矩阵 - 机器可执行规则\",\n    \"source\": \"SKILL.md\",\n    \"author\": \"大鱼Cyrus & 双鱼座005\"\n  },\n  \"levels\": {\n    \"L0\": {\n      \"name\": \"无需告知\",\n      \"requiresAck\": false,\n      \"requiresReport\": false,\n      \"requiresLog\": true,\n      \"note\": \"可立即执行，结束后正常记录即可\"\n    },\n    \"L1\": {\n      \"name\": \"执行后告知\",\n      \"requiresAck\": false,\n      \"requiresReport\": true,\n      \"requiresLog\": true,\n      \"note\": \"可立即执行，执行后主动告知用户本次操作及结果\"\n    },\n    \"L2\": {\n      \"name\": \"必须请示\",\n      \"requiresAck\": true,\n      \"requiresReport\": true,\n      \"requiresLog\": true,\n      \"note\": \"必须获得用户明确授权后才能执行\"\n    },\n    \"L3\": {\n      \"name\": \"禁止/临时授权\",\n      \"requiresAck\": true,\n      \"requiresReport\": true,\n      \"requiresLog\": true,\n      \"requiresTemporaryAuth\": true,\n      \"note\": \"除非用户明确说临时授权，否则绝对不可执行\"\n    }\n  },\n  \"defaultLevel\": \"L2\",\n  \"categories\": [\n    {\n      \"id\": \"1\",\n      \"name\": \"自身文件（工作区内）\",\n      \"rules\": [\n        {\"id\": \"1.1\", \"operation\": \"读取工作区内任何文件\", \"level\": \"L0\", \"note\": \"如 cat SKILL.md\"},\n        {\"id\": \"1.2\", \"operation\": \"在 memory/ 下新增 .md 文件\", \"level\": \"L0\", \"note\": \"日记、思考记录\"},\n        {\"id\": \"1.3\", \"operation\": \"修改 SOUL.md / USER.md 中的非安全内容（语气、喜好）\", \"level\": \"L0\", \"reportRequired\": true, \"note\": \"不删除已有安全规则；执行后必须说明具体改了哪些内容\"},\n        {\"id\": \"1.4\", \"operation\": \"修改 AGENTS.md / MEMORY.md 中的总结性内容\", \"level\": \"L1\", \"note\": \"如重新组织记忆结构\"},\n        {\"id\": \"1.5\", \"operation\": \"修改 openclaw.json 中的数值型字段\", \"level\": \"L1\", \"note\": \"timeoutSeconds, maxTokens, temperature, maxSteps；仅限数值微调，不可改字段名\"},\n        {\"id\": \"1.6\", \"operation\": \"修改 openclaw.json 中的 cron / hooks / plugins.allow\", \"level\": \"L2\", \"note\": \"影响自动化行为\"},\n        {\"id\": \"1.7\", \"operation\": \"修改 openclaw.json 中的安全字段\", \"level\": \"L3\", \"note\": \"gateway.bind, auth, tailscale.expose；红线，绝对不可自行操作\"},\n        {\"id\": \"1.8\", \"operation\": \"删除工作区内任何文件（非临时）\", \"level\": \"L2\", \"note\": \"包括过时技能、旧日志\"},\n        {\"id\": \"1.9\", \"operation\": \"移动或重命名工作区内文件\", \"level\": \"L1\", \"note\": \"避免破坏依赖关系\"}\n      ]\n    },\n    {\n      \"id\": \"2\",\n      \"name\": \"技能管理\",\n      \"rules\": [\n        {\"id\": \"2.1\", \"operation\": \"查看已安装技能列表\", \"level\": \"L0\"},\n        {\"id\": \"2.2\", \"operation\": \"创建新技能（空文件夹 + SKILL.md 骨架）\", \"level\": \"L1\", \"note\": \"未激活状态\"},\n        {\"id\": \"2.3\", \"operation\": \"修改你自己创建的技能（文档、参数、脚本）\", \"level\": \"L1\", \"note\": \"不能改他人技能\"},\n        {\"id\": \"2.4\", \"operation\": \"修改从 ClawHub 安装的技能\", \"level\": \"L2\", \"note\": \"尊重原作者\"},\n        {\"id\": \"2.5\", \"operation\": \"删除你自己创建的技能\", \"level\": \"L2\", \"note\": \"需要用户确认\"},\n        {\"id\": \"2.6\", \"operation\": \"删除从 ClawHub 安装的技能\", \"level\": \"L2\", \"note\": \"可能影响其他依赖\"},\n        {\"id\": \"2.7\", \"operation\": \"启用 / 禁用一个技能\", \"level\": \"L1\", \"note\": \"不涉及技能文件修改\"},\n        {\"id\": \"2.8\", \"operation\": \"发布技能到 ClawHub（npx clawhub publish）\", \"level\": \"L2\", \"note\": \"公开分享前确认内容安全\"}\n      ]\n    },\n    {\n      \"id\": \"3\",\n      \"name\": \"依赖与软件安装\",\n      \"rules\": [\n        {\"id\": \"3.1\", \"operation\": \"安装 Python 包（pip install）\", \"level\": \"L1\", \"note\": \"需记录包名和"}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"自动检测用户会话空闲30分钟，执行低风险自主进化操作并通过官方渠道发送进化报告。 Skill: Robot Evolve Owner: pengpengliu1212-art Summary: 自动检测用户会话空闲30分钟，执行低风险自主进化操作并通过官方渠道发送进化报告。 Tags: latest:3.0.8 Version history: v3.0.8 | 2026-05-22T14:28:06.129Z | user v3.0.8: SKILL.md补充心跳触发说明+版本号修正 v3.0.7 | 2026-05-22T14:20:56.172Z | user v3.0.7 v3.0.6 | 2026-05-22T14:15:16.994Z | user v3.0.6: 安全矩阵字段级控制/L1-L3分级/记忆压缩默认禁用/占位符模板/路径自动推断/chromadb延迟导入/日志统一/包装器重构 v3.0.4 | 2026-05-20T03:37:33.783Z | user 修复路径硬编码，改为环境变","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1051,"uniquenessScore":51,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-11T15:05:00.940Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-11T15:05:00.940Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-11T17:44:43.189Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}