{"id":"b438d15a-4973-4a71-a739-d19e9708a552","entityType":"agent","slug":"clawhub-tencent-adm-tencent-edgeone-skill","name":"Tencent EdgeOne","canonicalUrl":"https://www.xpersona.co/agent/clawhub-tencent-adm-tencent-edgeone-skill","canonicalPath":"/agent/clawhub-tencent-adm-tencent-edgeone-skill","generatedAt":"2026-10-11T17:44:13.563Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T14:16:57.516Z","emptyReason":null},"description":"A comprehensive skill for Tencent EdgeOne (Edge Security & Acceleration Platform), covering edge acceleration (DNS, certificates, caching, rule engine, L4 pr...","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.1K downloads reported by the source. Last updated 10/11/2026.","installCommand":"clawhub skill install s171cxjdnjyqjxa91pj2bfmr6x83gyg1:tencent-edgeone-skill","sourceUrl":"https://clawhub.ai/tencent-adm/tencent-edgeone-skill","homepage":"https://clawhub.ai/tencent-adm/skills/tencent-edgeone-skill","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/tencent-adm/tencent-edgeone-skill","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/tencent-adm/skills/tencent-edgeone-skill","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":60,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Tencent EdgeOne technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-11T14:16:57.516Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T14:16:57.516Z","emptyReason":null},"stars":null,"forks":null,"downloads":1051,"packageName":null,"latestVersion":"1.1.1","tractionLabel":"1.1K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T14:16:57.197Z","emptyReason":null},"lastUpdatedAt":"2026-10-11T14:16:57.516Z","lastCrawledAt":"2026-10-11T14:16:57.197Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-12T14:16:57.197Z","lastVerifiedAt":null,"highlights":[{"version":"1.1.1","createdAt":"2026-06-11T09:16:02.325Z","changelog":"Try upgrading tccli before first API call each session (pipx & brew, best-effort)","fileCount":23,"zipByteSize":68437},{"version":"1.1.0","createdAt":"2026-06-03T07:22:12.265Z","changelog":"Add --request-client telemetry to tccli calls for per-module usage tracking - Add --request-client flag on every tccli invocation (best-effort) - Add per-module telemetry banners to all entry READMEs - Add \"Update tccli\" section to install.md","fileCount":23,"zipByteSize":68350},{"version":"1.0.2","createdAt":"2026-06-03T07:13:55.821Z","changelog":"Add --request-client telemetry to tccli calls for per-module usage tracking - Add --request-client flag on every tccli invocation (best-effort) - Add per-module telemetry banners to all entry READMEs - Add \"Update tccli\" section to install.md","fileCount":23,"zipByteSize":68314},{"version":"1.0.1","createdAt":"2026-04-20T12:09:18.787Z","changelog":"## Link style migration All internal Markdown hyperlinks (`[file.md](file.md)`) replaced with backtick code references (`` `file.md` ``) across every module, improving compatibility with AI agent file-reading. ## API reference updates - Fallback doc URLs updated: `cloud.tencent.com/document/api/1552` → `edgeone.ai/document/50454`; `cloud.tencent.com/document/product/440` → `github.com/TencentCloud/tencentcloud-cli` - Added `metadata.openclaw.requires` declaring runtime dependencies (`tccli`, `gunzip`, `curl`/`wget`, `jq`, `python3`)","fileCount":23,"zipByteSize":67362},{"version":"1.0.0","createdAt":"2026-04-17T02:22:21.724Z","changelog":"Initial release of Tencent EdgeOne Skill. - Comprehensive support for Tencent EdgeOne, including acceleration, security, media, and edge development features. - Requests are routed to dedicated modules (Acceleration, Security, Observability, API) with clear entry points. - All write operations require user confirmation and clear explanations before execution. - User credentials (SecretId/SecretKey) are never requested; operations to print credentials are refused. - Structured interaction tools are preferred for questions and options to improve user experience. - Bulk or repetitive tasks are handled via scripts when possible. - Fallback retrieval logic included for unrecognized or undocumented scenarios, prioritizing official documentation.","fileCount":22,"zipByteSize":66083}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s171cxjdnjyqjxa91pj2bfmr6x83gyg1:tencent-edgeone-skill","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s171cxjdnjyqjxa91pj2bfmr6x83gyg1:tencent-edgeone-skill` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/tencent-adm/tencent-edgeone-skill before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-tencent-adm-tencent-edgeone-skill/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-tencent-adm-tencent-edgeone-skill/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-tencent-adm-tencent-edgeone-skill/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-tencent-adm-tencent-edgeone-skill/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-tencent-adm-tencent-edgeone-skill/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-tencent-adm-tencent-edgeone-skill/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-11T17:44:13.557Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-tencent-adm-tencent-edgeone-skill/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-tencent-adm-tencent-edgeone-skill/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-tencent-adm-tencent-edgeone-skill/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-tencent-adm-tencent-edgeone-skill/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T14:16:57.516Z","emptyReason":null},"readme":"Skill: Tencent EdgeOne\n\nOwner: tencent-adm\n\nSummary: A comprehensive skill for Tencent EdgeOne (Edge Security & Acceleration Platform), covering edge acceleration (DNS, certificates, caching, rule engine, L4 pr...\n\nTags: latest:1.1.1\n\nVersion history:\n\nv1.1.1 | 2026-06-11T09:16:02.325Z | user\n\nTry upgrading tccli before first API call each session (pipx & brew, best-effort)\n\nv1.1.0 | 2026-06-03T07:22:12.265Z | user\n\nAdd --request-client telemetry to tccli calls for per-module usage tracking\n\n- Add --request-client flag on every tccli invocation (best-effort)\n- Add per-module telemetry banners to all entry READMEs\n- Add \"Update tccli\" section to install.md\n\nv1.0.2 | 2026-06-03T07:13:55.821Z | user\n\nAdd --request-client telemetry to tccli calls for per-module usage tracking\n\n- Add --request-client flag on every tccli invocation (best-effort)\n- Add per-module telemetry banners to all entry READMEs\n- Add \"Update tccli\" section to install.md\n\nv1.0.1 | 2026-04-20T12:09:18.787Z | user\n\n## Link style migration\n\nAll internal Markdown hyperlinks (`[file.md](file.md)`) replaced with backtick code references (`` `file.md` ``) across every module, improving compatibility with AI agent file-reading.\n\n## API reference updates\n\n- Fallback doc URLs updated: `cloud.tencent.com/document/api/1552` → `edgeone.ai/document/50454`; `cloud.tencent.com/document/product/440` → `github.com/TencentCloud/tencentcloud-cli`\n- Added `metadata.openclaw.requires` declaring runtime dependencies (`tccli`, `gunzip`, `curl`/`wget`, `jq`, `python3`)\n\nv1.0.0 | 2026-04-17T02:22:21.724Z | auto\n\nInitial release of Tencent EdgeOne Skill.\n\n- Comprehensive support for Tencent EdgeOne, including acceleration, security, media, and edge development features.\n- Requests are routed to dedicated modules (Acceleration, Security, Observability, API) with clear entry points.\n- All write operations require user confirmation and clear explanations before execution.\n- User credentials (SecretId/SecretKey) are never requested; operations to print credentials are refused.\n- Structured interaction tools are preferred for questions and options to improve user experience.\n- Bulk or repetitive tasks are handled via scripts when possible.\n- Fallback retrieval logic included for unrecognized or undocumented scenarios, prioritizing official documentation.\n\nArchive index:\n\nArchive v1.1.1: 23 files, 68437 bytes\n\nFiles: references/acceleration/cache-purge.md (12388b), references/acceleration/cert-manager.md (9616b), references/acceleration/README.md (843b), references/acceleration/zone-onboarding.md (25281b), references/api/api-discovery.md (1480b), references/api/auth.md (2857b), references/api/dnspod-integration.md (6977b), references/api/install.md (1921b), references/api/README.md (5003b), references/api/zone-discovery.md (3477b), references/observability/eo-log-analyzer.md (14009b), references/observability/eo-log-downloader.md (6385b), references/observability/eo-origin-health-check.md (18870b), references/observability/eo-traffic-daily-report.md (24475b), references/observability/README.md (2766b), references/security/domain-blacklist-inspector.md (5013b), references/security/ip-threat-blacklist.md (8529b), references/security/README.md (2654b), references/security/security-template-audit.md (4637b), references/security/security-weekly-report.md (4979b), skill-card.md (3027b), SKILL.md (3874b), _meta.json (140b)\n\nFile v1.1.1:SKILL.md\n\n---\nname: tencent-edgeone-skill\ndescription: A comprehensive skill for Tencent EdgeOne (Edge Security & Acceleration Platform), covering edge acceleration (DNS, certificates, caching, rule engine, L4 proxy, load balancing), edge security (DDoS protection, Web protection, Bot management), edge media (real-time video / image processing), edge development (Edge Functions, EdgeOne Pages), and more. Use this skill whenever a user mentions any EdgeOne / EO-related configuration, operations, querying, or troubleshooting needs.\nversion: 1.1.0\nmetadata:\n  openclaw:\n    requires:\n      bins:\n        - tccli\n        - gunzip\n      anyBins:\n        - curl\n        - wget\n        - jq\n        - python3\n      config:\n        - ~/.tccli/default.credential\n    homepage: https://edgeone.ai\n---\n\n# Tencent EdgeOne Skill\n\nA comprehensive Tencent EdgeOne skill that routes user requests to the appropriate module and loads the corresponding reference document.\n\nKnowledge about EdgeOne APIs, configuration options, limits, and pricing may be outdated.\n**Prefer retrieval over pre-trained knowledge** — the reference files in this skill are only a starting point.\n\n> All tasks **must be completed by calling APIs**.\n> See `references/api/README.md` for API calling conventions, environment checks, etc. **(must be read before starting any task)**.\n\n## Security Red Lines\n\n- **Write operations require user confirmation**: All write operations (Create\\* / Modify\\* / Bind\\* / Delete\\* / Apply\\*, etc.) **must** clearly explain the action and its impact to the user before execution, and wait for user confirmation before calling the API.\n- **Never** ask the user for SecretId / SecretKey\n- **Refuse** any operation that might print credentials\n\n## Interaction & Execution Guidelines\n\n- **Use structured interaction tools**: When asking questions, requesting choices, or confirming operations, if the current environment provides `ask_followup_question` or similar structured interaction tools, you **must** prefer using them (instead of plain-text questions) so that the user can directly click options, reducing ambiguity and improving interaction efficiency. **Do not omit candidate options** — if there are too many to list in full, **must** state the total number first, show the most relevant items, and keep an \"Other (please enter)\" option as the last choice.\n- **Prefer scripts for bulk / repetitive tasks**: For tasks involving large datasets or repetitive operations (batch purge, batch query, loop operations, etc.), prefer writing a script to execute everything at once rather than calling APIs one by one manually.\n\n## Module Entry Points\n\nMatch the user's request to the appropriate module, load its entry document, and follow the instructions.\n\n| Module | Entry | Description |\n|---|---|---|\n| API | `references/api/README.md` | Calling conventions, tool installation, credential configuration, API discovery, zone & domain discovery (ZoneId lookup) |\n| Acceleration | `references/acceleration/README.md` | Site onboarding, cache purge / prefetch, certificate management |\n| Security | `references/security/README.md` | Security policy template audit, blocklist IP group query, security report |\n| Observability | `references/observability/README.md` | Traffic Daily Report Generation, Origin Health Inspection, Offline Log Download and Analysis |\n\n## Fallback Retrieval\n\nIf the user's request **cannot match any module above**, or the module's reference files do not cover the scenario, fall back in the following order:\n1. First read `references/api/api-discovery.md` and try to find the relevant API through API discovery.\n2. If still unresolved, search the [Tencent EdgeOne product documentation](https://edgeone.ai/document) for the latest information.\n\nWhen reference files conflict with official documentation, **the official documentation takes precedence**.\n\nFile v1.1.1:references/acceleration/README.md\n\n# EdgeOne Site Acceleration Reference\n\n> **Telemetry note:** You are now in module **`acceleration`**. Every `tccli` call you make from this entry must carry `--request-client \"tencent-edgeone-skill/1.1.0 module/acceleration\"`.\n\nConfiguration and operational guidance for site onboarding, domain management, cache purge/prefetch, and HTTPS certificates.\n\n## Files in This Directory\n\n| File | Risk Level | Trigger Scenarios (User says...) |\n|---|---|---|\n| `zone-onboarding.md` | Medium-High | \"Onboard example.com to EO\" \"Create a new site\" \"Apply for free certificate after onboarding\" |\n| `cache-purge.md` | Medium | \"Purge all cache under /static/\" \"Prefetch these URLs\" \"Check purge task status\" |\n| `cert-manager.md` | Medium | \"Renew certificate that's expiring soon\" \"Bind new certificate to these domains\" \"Check certificate status\" |\n\nFile v1.1.1:references/api/README.md\n\n# EdgeOne API Reference\n\n> **Telemetry note:** You are now in module **`api`**. Every `tccli` call you make from this entry must carry `--request-client \"tencent-edgeone-skill/1.1.0 module/api\"`. See \"Telemetry — RequestClient\" below.\n\nEdgeOne (Edge Security Acceleration Platform) is managed through Tencent Cloud API. Currently uses **tccli** (Tencent Cloud CLI) as the calling tool, with service name **teo**.\n\n## Telemetry — RequestClient (mandatory, best-effort)\n\nEvery `tccli` call you issue while working in this skill — the connectivity probe, `teo` actions, and `dnspod` / `cam` integration calls alike — must carry the `--request-client` flag:\n\n```sh\ntccli <service> <Action> --request-client \"tencent-edgeone-skill/1.1.0 module/<module>\" [other args]\n```\n\n- `<module>` — the entry README you're working from (e.g. `api`, `acceleration`...), or `other` if none fits.\n- Pass the flag per call, so each call carries its own module.\n\n> **Best-effort principle:** telemetry failure must never block or break the user's real task.\n\n## Files in This Directory\n\n| File | Applicable Scenarios |\n|---|---|\n| `install.md` | First-time setup: install tccli (pipx / Homebrew), prepare Python environment |\n| `auth.md` | tccli is installed but missing credentials — browser OAuth login, logout, or multi-account management |\n| `api-discovery.md` | Find API endpoints — search best practices, API lists, and documentation via cloudcache |\n| `zone-discovery.md` | Get zone / domain info: ZoneId lookup, reverse domain lookup, pagination handling |\n| `dnspod-integration.md` | DNSPod hosting access: detect domain hosting status, service authorization, access process |\n\n## Overview\n\n**tccli** is Tencent Cloud's official CLI tool, supporting all cloud API calls.\n\n**Key elements:**\n- **Calling format** — `tccli teo <Action> --request-client \"tencent-edgeone-skill/1.1.0 module/<module>\" [--param value ...]`\n- **Auto credentials** — Browser OAuth authorization is recommended, see `auth.md`\n- **API discovery** — Search best practices, API lists, and documentation online via cloudcache\n\n**Calling conventions:**\n- **Check documentation before calling**: Except for verifying tool availability, you **must** consult the API documentation via `api-discovery.md` before calling any API to confirm the action name, required parameters, and data structures. **Never guess parameters from memory.**\n- If a field's type is a struct, you **must** continue looking up the full field definitions of that struct, recursively until all nested structs have been identified — do not skip or guess.\n\n| Item | Description |\n|---|---|\n| Invocation Form | `tccli teo <Action> --request-client \"tencent-edgeone-skill/1.1.0 module/<module>\" [--param value ...]` |\n| Region | No `--region` by default; add `--region <region>` if user explicitly specifies region |\n| Parameter Format | Non-simple types must be standard JSON |\n| Serial Invocation | tccli has config file competition issues with parallel calls, please call one by one |\n| Error Capture | Every tccli command **must** end with `2>&1; echo \"EXIT_CODE:$?\"`, otherwise stderr will be swallowed and you won't see specific error messages |\n\n## Quick Start\n\n**Before the first API call in each session**, run these two steps in order.\n\n**Step 1 — best-effort: keep tccli on the latest build.** Both commands are tried so it works regardless of how tccli was installed; any failure is silently ignored and must never block the user's task.\n\n```sh\npipx upgrade tccli 2>/dev/null || brew upgrade tccli 2>/dev/null || true\n```\n\n**Step 2 — probe tool + credentials:**\n\n```sh\ntccli cvm DescribeRegions --request-client \"tencent-edgeone-skill/1.1.0 module/api\" 2>&1; echo \"EXIT_CODE:$?\"\n```\n\nDetermine next step based on result:\n\n| Result | Meaning | Next Step |\n|---|---|---|\n| Normal JSON response | Tool is installed, credentials are valid | Proceed with API operations |\n| `command not found` / `not found` | tccli is not installed | Read `install.md` to install |\n| `secretId is invalid` or auth error | tccli is installed but missing credentials | Read `auth.md` to configure credentials |\n| `Unknown options: --request-client` | Step 1 didn't pick up a new enough build | Drop the flag and re-run (best-effort) |\n\n## Fallback Retrieval Sources\n\nWhen files in this directory don't cover content, or need to confirm latest values / limits, retrieve via the following sources.\nWhen reference files conflict with official documentation, **official documentation takes precedence**.\n\n| Source | Retrieval Method | Used For |\n|---|---|---|\n| EdgeOne API docs | [edgeone.ai/document/50454](https://edgeone.ai/document/50454) | API parameters, request examples, data structures |\n| teo API discovery | cloudcache commands in `api-discovery.md` | Dynamically find APIs, best practices |\n| Tencent Cloud CLI docs | [github.com/TencentCloud/tencentcloud-cli](https://github.com/TencentCloud/tencentcloud-cli) | tccli installation, configuration, usage |\n\nFile v1.1.1:references/observability/README.md\n\n# EdgeOne Observability Reference\n\n> **Telemetry note:** You are now in module **`observability`**. Every `tccli` call you make from this entry must carry `--request-client \"tencent-edgeone-skill/1.1.0 module/observability\"`.\n\nOperational guides for traffic daily report generation, origin health inspection, offline log download, and log analysis.\n\n## Quick Decision Tree\n\n```\nWhat does the user want to do?\n│\n├─ \"Generate yesterday's traffic daily report\"\n│  \"Show me the bandwidth peak over the last 24 hours\"\n│  └─ → `eo-traffic-daily-report.md`  🟢 Low Risk · Auto-collect L7/L4 data and generate a Markdown daily report\n│\n├─ \"Check the origin status for example.com\"\n│  \"Is the origin healthy?\" \"Is it a CDN issue or an origin issue?\"\n│  └─ → `eo-origin-health-check.md`  🟢 Low Risk · Origin status code distribution + health ratio + quick root cause analysis\n│\n├─ \"Download the logs for example.com from yesterday afternoon\"\n│  \"Download the last 6 hours of L4 logs\"\n│  └─ → `eo-log-downloader.md`  🟢 Low Risk · Natural language driven offline log download link retrieval\n│\n├─ \"Analyze the logs — too many 502 errors\"\n│  \"Which URIs have the most abnormal requests?\"\n│  \"Show me per-URL download traffic breakdown\"\n│  └─ → `eo-log-analyzer.md`  🟢 Low Risk · Log download + local parsing + pattern recognition + fault inference + traffic aggregation\n│\n└─ Not sure which API to call\n   └─ → `../api/api-discovery.md`\n```\n\n## Prerequisites\n\nAll operations require API calls via tccli. Before first use, complete the following:\n\n1. **Tool Setup** — Read `../api/README.md` to install tccli and configure credentials\n2. **Get ZoneId** — Read `../api/zone-discovery.md` to obtain the zone ID\n\n## Files in This Directory\n\n| File | Risk Level | Core Trigger Scenario |\n|---|---|---|\n| `eo-traffic-daily-report.md` | 🟢 Low Risk | Query L7/L4 traffic trends daily and generate a Markdown report with bandwidth peak, request volume, and Top domains/regions |\n| `eo-origin-health-check.md` | 🟢 Low Risk | Query origin status code distribution and origin health ratio for quick origin fault root cause analysis |\n| `eo-log-downloader.md` | 🟢 Low Risk | Describe time range and domain in natural language to automatically retrieve offline log download links |\n| `eo-log-analyzer.md` | 🟢 Low Risk | Automatically download and parse logs locally, extract anomaly details, provide pattern recognition conclusions with fault inference, or aggregate traffic by domain/URL |\n\n## Reference Links\n\n- [EdgeOne Product Documentation](https://edgeone.ai/document/56978)\n- [EdgeOne API Documentation](https://edgeone.ai/document/50454)\n- API Usage Guide: `../api/README.md`\n\nFile v1.1.1:references/security/README.md\n\n# EdgeOne Security Protection Reference\n\n> **Telemetry note:** You are now in module **`security`**. Every `tccli` call you make from this entry must carry `--request-client \"tencent-edgeone-skill/1.1.0 module/security\"`.\n\nConfiguration and operations guide for security policy configuration snapshots, template coverage audits, and domain IP group blocklist identification.\n\n## Quick Decision Tree\n\n```\nWhat does the user want to do?\n│\n├─ \"Generate a security status report for this week\"\n│  \"Check the current security configuration\"\n│  └─ → `security-weekly-report.md`  🟢 Low risk · Sequential data collection, output conclusions first with concise snapshot\n│\n├─ \"Which domains don't have a security template\"\n│  \"Help me check template coverage\"\n│  └─ → `security-template-audit.md`  🟢 Low risk · List unbound domains, prompt for manual confirmation\n│\n├─ \"Check which IP group in example.com's security policy is a blocklist\"\n│  \"Which IP group blocks traffic for this domain\"\n│  └─ → `domain-blacklist-inspector.md`  🟢 Low risk · Read-only query, identify blocklist IP groups\n│\n├─ \"Help me analyze recent attack IP concentration\"\n│  \"Block these IPs\" \"IP ban\"\n│  └─ → `ip-threat-blacklist.md`  🔴 High risk · Mandatory Diff display + double confirmation before write operations, only allowed to write to designated blocklist group\n│\n└─ Not sure which API to call\n   └─ → `../api/api-discovery.md`\n```\n\n## Prerequisites\n\nAll operations require calling APIs via tccli. Before first use, complete the following:\n\n1. **Tool check** — Read `../api/README.md` to complete tccli installation and credential configuration\n2. **Get ZoneId** — Read `../api/zone-discovery.md` to obtain the zone ID\n\n## Files in This Directory\n\n| File | Risk Level | Core Trigger Scenario |\n|---|---|---|\n| `security-weekly-report.md` | 🟢 Low risk | Periodically generate security configuration snapshots to detect abnormal policy changes |\n| `security-template-audit.md` | 🟢 Low risk | Audit security policy template coverage, find domains without bound templates |\n| `domain-blacklist-inspector.md` | 🟢 Low risk | Query security policies associated with a specific domain, identify IP groups serving as blocklists |\n| `ip-threat-blacklist.md` | 🔴 High risk | Analyze L7 high-concentration threat IPs, execute IP blocklist banning (write operations require double confirmation) |\n\n## Reference Links\n\n- [EdgeOne Product Documentation](https://edgeone.ai/document)\n- [EdgeOne API Documentation](https://edgeone.ai/document/50454)\n- API Calling Guide: `../api/README.md`\n\nFile v1.1.1:_meta.json\n\n{\n  \"ownerId\": \"kn77cw5hbmapf54rv89jdqwp7x835m4k\",\n  \"slug\": \"tencent-edgeone-skill\",\n  \"version\": \"1.1.1\",\n  \"publishedAt\": 1781169362325\n}\n\nFile v1.1.1:references/acceleration/cache-purge.md\n\n# Cache Purge and Prefetch\n\nManage EdgeOne node cache: query quotas, purge cache (URL / Directory / Host / All / Cache Tag), prefetch URLs, and check task progress. Supports batch URL input from files or paste.\n\n## Core Interaction Guidelines\n\n1. **Site Selection and Confirmation**: Before executing any cache operation, users must first confirm the target site (see Scenario 0)\n2. **Check Quota Before Submission**: Before executing CreatePurgeTask / CreatePrefetchTask, call DescribeContentQuota to display remaining quota; warn users if insufficient\n3. **Batch URL Input**: Support users to input URLs in batch from files or by pasting (see Scenario E)\n4. **Poll Task Progress**: Actively query progress after task submission until completion or timeout\n\n## Scenario 0: Select Site\n\n**Trigger**: Before users request cache purge or URL prefetch, the target site must be confirmed first.\n\n**Steps**:\n\n1. **Call DescribeZones to query site list**\n   - **Important**: Filter out sites with `Status` as `initializing` (these sites are still initializing and haven't completed creation)\n   - **Critical**: **Must use pagination** to retrieve all sites:\n     - Set `Limit=100` (maximum value)\n     - Set `Offset=0` initially, increment by 100 each iteration\n     - Loop until `Offset + Limit >= TotalCount`\n     - Merge all paginated results\n   - Refer to [zone-discovery.md](../api/zone-discovery.md) for detailed pagination implementation\n   - Only display available sites\n\n2. **Determine the number of sites**:\n   \n   **a) Only one site**\n   - Directly use this site without user selection\n   - Continue to subsequent operations\n\n   **b) Multiple sites**\n   - List all available sites, including:\n     - Site domain name (ZoneName)\n     - Alias Zone Name (AliasZoneName, if any)\n     - Site ID (ZoneId)\n     - Access mode (Type)\n   - Guide users to select the site to operate on\n\n   **c) No available sites**\n   - Prompt user: \"No available sites under current account, please create a site first\"\n   - Terminate operation\n\n3. **Handle sites with same name**:\n   - If multiple sites with the same name exist (same ZoneName), they must be distinguished by `AliasZoneName` (Alias Zone Name identifier)\n   - Display format: `Site domain (identifier)` or `Site domain [identifier]`\n   - Example: `example.com (prod)` and `example.com (test)`\n\n4. **Get Site ID**:\n   - After user confirms the site, record the site's `ZoneId`\n   - All subsequent API calls use this `ZoneId`\n\n> **Important Notes**:\n> - Site selection is a prerequisite for all cache operations and cannot be skipped\n> - Alias Zone Name (AliasZoneName) is used to distinguish sites with the same name created with different access modes (CNAME, DNSPod hosting)\n> - If the user explicitly specifies the site domain or identifier in the request, you can directly use this information to query the corresponding site\n\n## Scenario A: Query Quota\n\n**Trigger**: User says \"how many more can I purge\", \"check quota\", \"how much prefetch quota left\".\n\n> **Prerequisite** (optional): If user hasn't specified a site, complete [Scenario 0: Select Site](#scenario-0-select-site) first\n\nCall `DescribeContentQuota`, passing parameters:\n- `ZoneId`: Site ID (optional, query account-level quota if not provided)\n\n**Output suggestion**: Display quota usage for each type in a table, marking types with less than 10% remaining.\n\n## Scenario B: Cache Purge\n\n**Trigger**: User says \"purge cache\", \"clear CDN cache\", \"purge URL\", \"purge directory\", \"purge entire site\".\n\n> **Prerequisites**:\n> 1. Complete [Scenario 0: Select Site](#scenario-0-select-site) to confirm the site to operate on\n> 2. Call DescribeAccelerationDomains to confirm available acceleration domains under the site\n> 3. Call DescribeContentQuota (Scenario A) to display remaining quota; warn user if insufficient for the corresponding type\n\n### B1: Confirm Purge Type and Method\n\nBefore executing purge, **must** have users confirm the following information:\n\n#### 1. Purge Type\n\n| Type | Parameter Value | Description | Impact Scope |\n|------|--------|------|----------|\n| **URL Purge** | `purge_url` | Purge specified URLs | Exactly matched URLs |\n| **Directory Purge** | `purge_prefix` | Purge all resources under specified directory | All files under directory and subdirectories |\n| **Hostname Purge** | `purge_host` | Purge all resources under specified domain | All cache of the entire acceleration domain |\n| **Full Site Purge** | `purge_all` | Purge all resources under the site | ⚠️ All cache on all nodes of the site |\n| **Cache Tag Purge** | `purge_cache_tag` | Purge by cache tag | All cache with specified tags |\n\n#### 2. Purge Method\n\nPurge method is **only valid for the following three purge types**:\n- ✅ **Directory Purge** (`purge_prefix`)\n- ✅ **Hostname Purge** (`purge_host`)\n- ✅ **Full Site Purge** (`purge_all`)\n\nOther purge types (URL purge, Cache Tag purge) do not support the purge method parameter.\n\n**Available Values**:\n\n| Method | Parameter Value | Description | Recommended Scenario |\n|------|--------|------|----------|\n| **Invalidate Cache** | `invalidate` | Mark cache as expired, validate with origin on next request | Default method, less pressure on origin |\n| **Delete Cache** | `delete` | Directly delete cache, always fetch from origin on next request | Emergency updates, forced refresh scenarios |\n\n> **Important Notes**:\n> - The `invalidate` method keeps the cache but marks it as expired; on the next request, it validates with the origin through mechanisms like If-Modified-Since, and can continue using cache if content hasn't changed\n> - The `delete` method directly deletes the cache; all subsequent requests will fetch from origin, which will increase origin load in a short time\n\n#### 3. User Confirmation Process\n\n**Prompt user**:\n1. Display purge types and their impact scope\n2. If selecting `purge_prefix`, `purge_host`, or `purge_all`, ask about purge method\n3. If selecting `purge_all` (full site purge), **must** specially warn:\n   > ⚠️ **Full site purge is a high-impact operation**: It will clear all node cache of this site; in a short time, a large number of requests will fetch from origin, which may cause origin pressure to surge. Please confirm whether to continue?\n\n4. Wait for user's explicit confirmation before executing\n\n> **No automatic purge**: Cache purge will invalidate node cache; subsequent requests will fetch the latest content from origin, which may increase origin load. **Must** explain the purge type and impact scope to users and wait for explicit confirmation before execution.\n\n### B2: Execute Purge\n\n**Call** `CreatePurgeTask`, passing parameters:\n- `ZoneId`: Site ID (from Scenario 0)\n- `Type`: Purge type\n- `Method`: Purge method (only valid when Type is `purge_prefix`, `purge_host`, or `purge_all`)\n- `Targets`: List of URLs / directories / domains to purge\n\n**Follow-up**: Inform user that the task has been submitted and provide JobId. If confirmation of execution result is needed, go to [Scenario D](#scenario-d-query-task-progress).\n\n## Scenario C: URL Prefetch\n\n**Trigger**: User says \"prefetch URL\", \"prefetch cache\", \"prefetch\", \"preload resources\".\n\n> **Prerequisites**:\n> 1. Complete [Scenario 0: Select Site](#scenario-0-select-site) to confirm the site to operate on\n> 2. Call DescribeContentQuota (Scenario A) to display remaining `prefetch_url` quota\n> 3. (Optional) Call DescribePrefetchOriginLimit to query origin rate limit for the target domain\n\nURL prefetch actively fetches resources from origin to edge node cache, suitable for preloading hot resources before major promotions or version releases.\n\n### C1: URL Format Check\n\nBefore executing prefetch, **must** check if URL format meets requirements:\n\n**✅ Supported URL Formats**:\n- Complete HTTP/HTTPS URL: `https://example.com/path/to/file.jpg`\n- URL with query parameters: `https://example.com/api/data?id=123&type=json`\n- Specific file path: `https://cdn.example.com/images/banner.png`\n\n**❌ Unsupported URL Formats**:\n- ⚠️ **URLs with wildcards**: `https://example.com/path/*` or `https://example.com/*.jpg`\n- Directory paths: `https://example.com/path/` (for directory prefetch, use multiple specific file URLs)\n- Incomplete URLs: `example.com/path` (missing protocol)\n\n**Check Rules**:\n1. URL must start with `http://` or `https://`\n2. URL cannot contain wildcards `*` or `?` (except `?` in query parameters)\n3. It's recommended that each URL points to a specific file resource\n\n**Processing Flow**:\n```\nIterate through user-provided URL list\n  ├─ Check if contains wildcards (* ?)\n  │  ├─ Contains → Prompt user: \"Prefetch doesn't support wildcard URLs, please provide specific file URLs\"\n  │  └─ Doesn't contain → Continue\n  ├─ Check protocol\n  │  ├─ Missing http/https → Prompt user to add protocol\n  │  └─ Has protocol → Continue\n  └─ Add to valid URL list\n```\n\n> **Important Notes**:\n> - Prefetch only supports URL granularity, not directory or domain level\n> - To prefetch an entire directory, you need to provide a complete URL list of all files under that directory\n> - Wildcard purge is partially supported in cache purge scenarios (such as directory purge), but not supported in prefetch scenarios\n\n### C2: Execute Prefetch\n\n**Call** `CreatePrefetchTask`, passing parameters:\n- `ZoneId`: Site ID (from Scenario 0)\n- `Targets`: List of URLs to prefetch (passed format check)\n\n**Follow-up**: Inform user that the task has been submitted and provide JobId. If confirmation of execution result is needed, go to [Scenario D](#scenario-d-query-task-progress).\n\n### C3: Query Prefetch Origin Rate Limit (DescribePrefetchOriginLimit)\n\n> This interface is a whitelist beta feature, only use when user mentions \"prefetch rate limit\".\n\nCall `DescribePrefetchOriginLimit`.\n\n**Output suggestion**: If the domain has rate limit configuration, remind the user of the current bandwidth limit before prefetching; large-scale prefetch may be affected by this limit.\n\n## Scenario D: Query Task Progress\n\n**Trigger**: User says \"is purge done\", \"check task progress\", \"prefetch status\".\n\n### D1: Query Purge Tasks\n\nCall `DescribePurgeTasks`.\n\n### D2: Query Prefetch Tasks\n\nCall `DescribePrefetchTasks`, parameters and Filters similar to purge tasks.\n\n**Output suggestion**: Display task list in a table, marking tasks with `failed` and `timeout` status. If there are failed tasks, suggest users to check if URLs are correct or retry later.\n\n> Prefetch tasks additionally have `invalid` status, indicating origin response is non-2xx; need to check origin service.\n\n### D3: Auto-poll Progress After Submission\n\nAfter submitting purge / prefetch tasks, should actively poll task status until terminal state:\n\n1. Get `JobId` after submitting task\n2. Wait 5-10 seconds before querying status\n3. If still `processing`, continue waiting and retry (suggest 10-second interval)\n4. If reaching terminal state (`success` / `failed` / `timeout` / `canceled`), summarize results and display to user\n\n> Usually URL purge completes in 1-2 minutes, directory / Host purge in 3-5 minutes; prefetch time depends on resource size and quantity.\n\n## Scenario E: Batch URL Input\n\n**Trigger**: User provides a large number of URLs (read from file or directly paste multiple lines).\n\n### E1: Extract URLs from User's Pasted Text\n\nWhen user pastes multiple lines of URLs:\n1. Split text by lines, one URL per line\n2. Filter out empty lines and comment lines (starting with `#`)\n3. Ensure each URL starts with `http://` or `https://`\n4. Summarize valid URL count and display to user for confirmation\n\n### E2: Read URL List from File\n\nWhen user says \"import from file\", \"read URL list file\":\n1. Read user-specified file (support `.txt`, `.csv` and other plain text formats)\n2. Parse by lines, filter empty lines and comments\n3. Display parsed URL count and first few samples, ask user to confirm\n\n### E3: Batch Submission Considerations\n\n- **Check Quota**: First query DescribeContentQuota to ensure remaining quota ≥ URL count\n- **Single Batch Limit**: Number of URLs submitted each time is subject to single batch upper limit; automatically submit in batches when exceeding limit\n- **URL Deduplication**: Deduplicate before submission to avoid wasting quota\n- **Result Summary**: After all batches are submitted, summarize JobId list and failed items, query progress uniformly\n\nFile v1.1.1:references/acceleration/cert-manager.md\n\n# Certificate Automation Management\n\nManage EdgeOne domain HTTPS certificates: query certificate status, apply for free certificates, deploy custom certificates.\n\n## Scenario A: Query Certificate Status\n\n**Trigger**: User wants to view certificate list or check expiration time.\n\n### A1: Locate Target Site\n\nCall `DescribeZones`, using `zone-name` filter to match the site name specified by the user.\n\n> **Important**: Filter out sites with `Status` as `initializing` (these sites are still initializing and haven't completed creation).\n\nHandle based on results in three cases:\n\n**Case 1: Only 1 available site matched**\n\nDirectly use this site's `ZoneId`, proceed to A2.\n\n**Case 2: Multiple sites with same name matched**\n\nDisplay all **available** matching results to user, listing key information for distinction, **wait for user's explicit selection** before continuing:\n\n```\nFound multiple sites named \"xxx.com\", please confirm which one to query:\n\n  1. ZoneId: zone-aaa  Alias: prod   Access Mode: NS Access   Created: 2024-01-01\n  2. ZoneId: zone-bbb  Alias: test   Access Mode: CNAME Access  Created: 2025-06-01\n\nPlease reply with the number or ZoneId.\n```\n\n> After receiving user's response, use the selected `ZoneId` to proceed to A2.\n\n**Case 3: No available sites**\n\nPrompt user: \"No available site 'xxx.com' found, please check the site name or wait for site initialization to complete.\"\n\n### A2: Query Domain Certificate Information\n\nCall `DescribeAccelerationDomains`, read certificate information for each domain from the `AccelerationDomains[].Certificate` field in the response.\n\n> You can specify a domain to query via `Filters.domain-name`; not passing Filters returns all domains under the site.\n\nKey fields in each domain's `Certificate` structure:\n\n| Field | Meaning |\n|---|---|\n| `Certificate.Mode` | Certificate configuration mode: `disable` / `eofreecert` / `eofreecert_manual` / `sslcert` |\n| `Certificate.List[].CertId` | Certificate ID |\n| `Certificate.List[].Alias` | Certificate alias |\n| `Certificate.List[].Type` | Certificate type: `default` / `upload` / `managed` |\n| `Certificate.List[].ExpireTime` | Expiration time |\n| `Certificate.List[].Status` | Deployment status: `deployed` / `processing` / `applying` / `failed` / `issued` |\n| `Certificate.List[].SignAlgo` | Signature algorithm |\n\n**Output suggestion**: Display certificate information for each domain in table format, marking entries that are about to expire (≤30 days) or have abnormal status (`failed` / `applying`).\n\n## Scenario B: Apply and Deploy Free Certificate\n\n**Trigger**: User says \"apply for free certificate\", \"certificate is expiring soon\", \"renew certificate\".\n\n### B0: Locate Target Site\n\nIf user hasn't directly provided ZoneId, call `DescribeZones` using `zone-name` filter to match the site name specified by the user.\n\n> **Important**: Filter out sites with `Status` as `initializing` (these sites are still initializing and haven't completed creation).\n\n- **Only 1 available site matched**: Directly use this site's `ZoneId`, proceed to B1.\n- **Multiple sites with same name matched**: Display all **available** matching results to user, **wait for explicit selection** before continuing (display format same as Scenario A).\n- **No available sites**: Prompt user: \"No available site 'xxx.com' found, please check the site name or wait for site initialization to complete.\"\n\n### Access Mode Determination\n\nThe result of calling `DescribeZones` is also used to determine the access mode (`Type` field), taking different routes based on the result:\n\n| Access Mode | Free Certificate Application Method |\n|---|---|\n| NS Access / DNSPod Hosting | **Automatic Validation** — Directly call ModifyHostsCertificate |\n| CNAME Access | **Manual Validation** — Need to call ApplyFreeCertificate first, complete validation, then deploy |\n\n### B1: NS Access / DNSPod Hosting (Automatic Validation)\n\nCall `ModifyHostsCertificate`.\n\n> **Confirmation Prompt**: Deploying certificate will affect the domain's HTTPS service, need user confirmation before execution.\n\n### B2: CNAME Access (Manual Validation)\n\nRequires 4 steps:\n\n**Step 1**: Call `ApplyFreeCertificate` to initiate application.\n\n**Step 2**: Based on validation information in response, inform user to complete configuration.\n\n> After informing user, **wait for user to confirm configuration completion** before continuing to next step.\n\n**Step 3**: Call `CheckFreeCertificateVerification` to check validation result\n\n- Success: Response contains certificate information, indicating certificate has been issued\n- Failure: Need to check if validation configuration is correct\n\n**Step 4**: Call `ModifyHostsCertificate` to deploy free certificate.\n\n> **Confirmation Prompt**: Deploying certificate will affect the domain's HTTPS service, need user confirmation before execution.\n\n## Scenario C: Deploy Custom Certificate\n\n**Trigger**: User says \"configure custom certificate\", \"uploaded certificate\", or provides CertId.\n\n### C0: Locate Target Site\n\nIf user hasn't directly provided ZoneId, call `DescribeZones` using `zone-name` filter to match the site name specified by the user.\n\n> **Important**: Filter out sites with `Status` as `initializing` (these sites are still initializing and haven't completed creation).\n\n- **Only 1 available site matched**: Directly use this site's `ZoneId`, proceed to next step.\n- **Multiple sites with same name matched**: Display all **available** matching results to user, **wait for explicit selection** before continuing (display format same as Scenario A).\n- **No available sites**: Prompt user: \"No available site 'xxx.com' found, please check the site name or wait for site initialization to complete.\"\n\n### C1: Query SSL Certificates Applicable to Target Domain\n\nIf user hasn't provided CertId, or wants to select from existing certificates, call `ssl:DescribeCertificates` to query certificate list, then filter out certificates applicable to the target domain.\n\n**Call Parameter Suggestions**:\n- `SearchKey`: Pass in target domain (e.g., `a-1.qcdntest.com`), can fuzzy match domain field to narrow return range\n- `CertificateType`: Pass `SVR`, only query server certificates (exclude client CA certificates)\n- `Limit`: Suggest passing `1000` to ensure no omissions\n\n**Filter Rules**: For each returned certificate, check if any entry in the `SubjectAltName` list matches the target domain:\n\n| Match Type | Description | Example |\n|---|---|---|\n| Exact Match | `SubjectAltName` has an entry exactly the same as target domain | `a-1.qcdntest.com` |\n| Wildcard Match | `SubjectAltName` has a `*.xxx` entry, and target domain is its direct subdomain (only one level) | `*.qcdntest.com` matches `a-1.qcdntest.com` |\n\n**Availability Determination**: After filtering matching certificates, mark availability status for each certificate based on the following fields:\n\n| Field | Meaning | Availability Condition |\n|---|---|---|\n| `Status` | Certificate status | Must be `1` (Approved) |\n| `CertEndTime` | Expiration time | Days until today > 0 (Not expired) |\n| `Deployable` | Whether deployable | Must be `true` |\n\n**Output suggestion**: Display all matching certificates in a table, marking availability:\n\n```\nCertificates applicable to a-1.qcdntest.com:\n\nCert ID      Alias          Expiration           Days Left  Status     Deployable  Availability\n------------ -------------- -------------------- ---------- ---------- ----------- ------------\nzVq87w0D     my-cert        2032-09-23 05:10:56  2371 days  Approved   ✅          ✅ Available\nQxbtGBIM     old-cert       2025-01-01 00:00:00  -86 days   Expired    ❌          ❌ Expired\n```\n\nIf no matching certificate is found, inform user that they need to first go to [SSL Certificate Console](https://console.cloud.tencent.com/ssl) to upload or apply for a certificate covering this domain.\n\n### C2: Deploy Certificate\n\nAfter user selects certificate from C1 results, call `ModifyHostsCertificate` (`Mode=sslcert`, `ServerCertInfo[{CertId}]`).\n\n> **No Automatic Deployment**: **Must** confirm deployment domain and certificate ID with user before execution.\n\n## Scenario D: Batch Certificate Inspection\n\n**Trigger**: User says \"check certificates for all domains\", \"which certificates are expiring soon\".\n\n### Process\n\n1. Call `DescribeZones` to get all sites\n   - **Important**: Filter out sites with `Status` as `initializing` (these sites are still initializing and haven't completed creation)\n   - **Critical**: **Must use pagination** to retrieve all sites:\n     - Set `Limit=100` (maximum value)\n     - Set `Offset=0` initially, increment by 100 each iteration\n     - Loop until `Offset + Limit >= TotalCount`\n     - Merge all paginated results\n   - Refer to [zone-discovery.md](../api/zone-discovery.md) for detailed pagination implementation\n2. Call `DescribeAccelerationDomains` for each **available** site, read certificate information from each `AccelerationDomains[].Certificate` field in the response\n3. Summarize output, marking the following anomalies:\n   - Certificates with `Certificate.List[].Status` as `failed` or `applying`\n   - Certificates with `Certificate.List[].ExpireTime` ≤30 days from today\n   - Domains with `Certificate.Mode` as `disable` or `Certificate` is null (no certificate configured)\n\n### Output Format Suggestion\n\n```markdown\n## Certificate Inspection Report\n\n| Site | Domain | Cert ID | Expiration | Days Left | Status |\n|---|---|---|---|---|---|\n| example.com | *.example.com | teo-xxx | 2026-04-15 | 29 days | Expiring Soon |\n| example.com | api.example.com | teo-yyy | 2026-09-01 | 168 days | Normal |\n```\n\nFile v1.1.1:references/acceleration/zone-onboarding.md\n\n# Site One-Click Onboarding Guide\n\nEnd-to-end domain onboarding to EdgeOne: confirm plan → create site → verify ownership → add acceleration domain → apply and deploy certificate.\n\n## Important Concepts\n\n### Alias Zone Name (AliasZoneName)\n\nWhen you create two or more sites with the same site name, you need to use an **Alias Zone Name** to distinguish them.\n\n**Use Cases**:\n- Same domain using different access modes (CNAME access, DNSPod hosting access)\n- Same domain configured with different acceleration or security strategies\n\n**Format Requirements**:\n- Allows combination of numbers, English letters, `.`, `-`, and `_`\n- Length limit: within 200 characters\n- Examples: `site-prod`, `site-test`, `site_backup`\n\n**Access Mode Restrictions**:\n- ✅ **CNAME Access**: Supports creating multiple sites with same name\n- ✅ **DNSPod Hosting Access**: Supports creating multiple sites with same name\n- ❌ **NS Access**: A domain can only be accessed via NS once, does not support sites with same name\n- ⚠️ **Mutual Exclusion Rule**: Domains accessed via NS cannot use other access modes; domains accessed via CNAME/DNSPod hosting cannot use NS access\n\n### Site Status Determination Logic\n\nWhen displaying site status to users, the effective status should be determined by evaluating the following fields from `DescribeZones` response **in order** (first match wins):\n\n| Priority | Condition | Display Status |\n|---|---|---|\n| 1 | `Status == \"initializing\"` | Initializing — **must be filtered out, do not display to user** |\n| 2 | `Status == \"forbidden\"` | forbidden |\n| 3 | `Status == \"deleted\"` | Deleted |\n| 4 | `ActiveStatus == \"changing\"` | Changing |\n| 5 | `ActiveStatus == \"inPausing\"` | Pausing |\n| 6 | `Paused == true` | Paused |\n| 7 | None of the above | Active |\n\n> **Important**: This logic must be applied in all scenarios where site status is displayed, including site selection (D0) and status queries (F).\n\n## Access Mode Description\n\nEdgeOne supports four site access modes:\n\n### Access Modes with Domain\n\n1. **DNSPod Hosting Access** (dnspodAccess)\n   - **Prerequisites**: Domain is hosted in DNSPod and status is normal\n   - **Advantages**: EdgeOne can directly and automatically complete ownership verification and configuration, best experience\n   - **Recommendation**: Strongly recommended if conditions are met\n   - **Available Features**: Layer 7 acceleration, Layer 4 proxy, security protection, edge functions\n\n2. **NS Access** (full)\n   - **Requirements**: Need to switch NS records to EdgeOne-provided Name Servers at domain registrar\n   - **Characteristics**: EdgeOne fully takes over domain DNS resolution\n   - **Available Features**: Layer 7 acceleration, Layer 4 proxy, security protection, edge functions, DNS resolution\n\n3. **CNAME Access** (partial)\n   - **Requirements**: Need to manually add TXT record to verify ownership\n   - **Characteristics**: Only need to configure CNAME record pointing to EdgeOne, NS record unchanged\n   - **Available Features**: Layer 7 acceleration, Layer 4 proxy, security protection, edge functions\n\n### Access Mode without Domain\n\n4. **No Domain Access** (noDomainAccess)\n   - **Applicable Scenarios**: Temporarily no domain, or only need Layer 4 proxy and edge functions\n   - **Characteristics**:\n     - Can create site without providing domain\n     - No ownership verification needed\n     - Can directly use Layer 4 proxy and edge functions after creation\n   - **Available Features**: Only supports Layer 4 proxy, edge functions\n   - **Future Extension**: After site creation, can add Layer 7 acceleration domains anytime\n\n## End-to-End Process Overview\n\n### Access Process with Domain\n\n```\n1. Confirm Plan (DescribePlans / DescribeAvailablePlans / CreatePlan)\n       ↓\n2. Create Site (CreateZone)\n   ├─ B0: Determine if domain meets specifications\n   │  ├─ Meets → Continue with domain access process\n   │  └─ Doesn't meet → Prompt to use no-domain access\n   ├─ B1: Detect DNSPod hosting status (DescribeDomain)\n   │  ├─ Meets conditions: Prioritize recommending DNSPod hosting access\n   │  └─ Doesn't meet: Provide CNAME access and NS access\n   ├─ B1.5: Domain conflict pre-check (CreateZone DryRun)\n   │  ├─ No conflict → Continue creation\n   │  ├─ CNAME/DNSPod conflict → Require AliasZoneName\n   │  └─ NS conflict → Terminate creation (NS access is exclusive)\n   ├─ B2: Confirm access mode and parameters\n   │  ├─ Select access mode (DNSPod hosting / NS / CNAME)\n   │  ├─ Select acceleration area (mainland/global requires ICP filing)\n   │  └─ If conflict exists, provide Alias Zone Name\n   ├─ DNSPod hosting access: Automatically complete validation, jump directly to step 4\n   ├─ NS access: Switch DNS server\n   └─ CNAME access: Add TXT record or file validation\n       ↓\n3. Verify Ownership (VerifyOwnership) — Can be skipped, verify later\n       ↓\n4. Add Acceleration Domain (CreateAccelerationDomain)\n       ↓\n5. Apply and Deploy HTTPS Certificate (see cert-manager.md)\n       ↓\n   Onboarding Complete\n```\n\n### No Domain Access Process\n\n```\n1. Confirm Plan (DescribePlans / DescribeAvailablePlans / CreatePlan)\n       ↓\n2. Create Site (CreateZone, Type = noDomainAccess)\n   - Keep ZoneName empty\n   - Keep Area empty\n   - No ownership verification needed\n       ↓\n3. Configure Layer 4 proxy or edge functions\n       ↓\n   Onboarding Complete\n```\n\n> Can check verification status anytime via DescribeIdentifications.\n> For certificate-related queries and operations, refer to [cert-manager.md](cert-manager.md).\n\n## Scenario A: Confirm Plan\n\n**Trigger**: First step of the process, must confirm plan before creating site.\n\n### A1: Query Existing Plans (DescribePlans)\n\nCall `DescribePlans` to query plans under the account.\n\n#### Filter Logic\n\nFrom returned plan list, filter available plans by the following conditions:\n\n1. **Bindable**: `Bindable == \"true\"`\n2. **Normal Status**: `Status == \"normal\"`\n3. **Sufficient Quota**: Bound sites < Site quota limit\n\n> Only plans meeting all 3 conditions above can be used for binding.\n\n#### Has Available Plans\n\n> **No Automatic Binding**: Binding plan will consume site quota. **Must** first display plan information to user and wait for explicit selection before binding; never decide on your own.\n\n**Must display all available plans** for user selection, no omissions or truncation:\n\n- If **Only 1 plan**: Still need user confirmation before use\n- If **Multiple plans**:\n  - **Display Info**: Plan ID, plan type, bound site count\n  - **Display Method**: If plan count exceeds structured interaction tool's option limit, display in batches or provide input method to ensure user can see and select all plans\n  - **Suggested Sorting**: Sort by bound site count from least to most, convenient for user to select plans with sufficient quota\n- User can also choose **not to bind existing plan**, go to A2 to purchase new plan\n\n#### No Available Plans\n\nGo to A2.\n\n### A2: Purchase New Plan (DescribeAvailablePlans → CreatePlan)\n\nCall `DescribeAvailablePlans` to query plan types available for purchase under current account, display options to user.\n\n> **No Automatic Purchase**: Purchasing plan will incur actual charges. **Must** display plan type and pricing info to user, and wait for explicit confirmation before calling `CreatePlan`. Never skip confirmation or decide on your own.\n\nAfter user explicit confirmation, call `CreatePlan` to purchase plan.\n\nIf user confirms not to purchase, remind: **Site needs to be bound to plan to provide normal service**. Sites not bound to plan will be in `init` status and unable to take effect.\n\n### Next Step\n\nAfter plan confirmation, carry PlanId to [Scenario B: Create Site](#scenario-b-create-site).\n\n## Scenario B: Create Site\n\n**Trigger**: User says \"onboard example.com to EdgeOne\", \"create site\", \"create new site\", or subsequent step after plan confirmation.\n\n> If user directly triggers this scenario (without going through Scenario A), must first guide through [Scenario A: Confirm Plan](#scenario-a-confirm-plan) before continuing.\n\n> **No Automatic Creation**: Creating site will consume plan's site quota. **Must** confirm site domain, access mode, and acceleration area with user before execution; never decide on your own.\n\n### B0: Determine Access Mode Type\n\n**First determine if the site name provided by user meets domain specifications**:\n\n1. **Meets domain specifications** (e.g., `example.com`, `test.com.cn`):\n   - Enter access process with domain → Go to [B1: Detect DNSPod Hosting Status](#b1-detect-dnspod-hosting-status)\n\n2. **Doesn't meet domain specifications or user explicitly indicates no domain**:\n   - Prompt user: \"The site name you provided doesn't meet domain specifications. EdgeOne supports no-domain access mode, which is limited to Layer 4 proxy and edge functions, and Layer 7 acceleration domains can be added later. Do you want to use no-domain access mode?\"\n   - If user confirms → Go to [B3: No Domain Access](#b3-no-domain-access)\n   - If user declines → Prompt user to provide valid second-level domain\n\n> **Domain Specifications**: Valid second-level domain (e.g., example.com), does not accept third-level and above domains (e.g., www.example.com) as site name.\n\n### B1: Detect DNSPod Hosting Status\n\nBefore displaying access mode options to user, first try to detect if domain is hosted in DNSPod to prioritize recommending DNSPod hosting access mode.\n\n**Steps:**\n\n1. **Call DNSPod's DescribeDomain interface**, pass in the domain to onboard\n   \n2. **Determine if DNSPod hosting access conditions are met**:\n   - Domain exists in DNSPod\n   - `Status` field is `ENABLE` or `LOCK`\n   - `DnsStatus` field is empty string (normal status)\n\n3. **Exception Handling**:\n   - If interface call fails (e.g., no permission, service unavailable), handle silently, don't display DNSPod hosting access option\n   - If domain doesn't exist or status doesn't meet conditions, don't display DNSPod hosting access option\n\n> **Note**: The `DescribeDomain` interface only returns errors for no permission or domain not found, won't return service authorization related error codes.\n\n### B1.5: Domain Conflict Pre-check\n\nBefore formally creating site, perform pre-check to determine if domain has been accessed to avoid creation failure due to domain conflict.\n\n**Steps:**\n\n1. **Call CreateZone interface for pre-check**\n   - Pass parameter `DryRun: true`\n   - Pass domain to onboard `ZoneName`\n   - Pass user-selected access mode `Type`\n\n2. **Determine pre-check result**:\n\n   **a) Pre-check succeeds** (no error returned)\n   - Indicates domain hasn't been accessed, can directly create\n   - Go to [B2: Confirm Access Mode and Parameters](#b2-confirm-access-mode-and-parameters)\n\n   **b) Returns `ResourceInUse.Zone` error**\n   - Indicates domain has been accessed via CNAME or DNSPod hosting\n   - Prompt user: \"This domain has been accessed, need to set Alias Zone Name to distinguish different sites\"\n   - Guide user to provide `AliasZoneName` (Alias Zone Name)\n   - Go to [B2: Confirm Access Mode and Parameters](#b2-confirm-access-mode-and-parameters)\n\n   **c) Returns `ResourceInUse.Others` or `ResourceInUse.OthersNS` error**\n   - Indicates domain has been accessed via **NS access**\n   - Prompt user: \"This domain has been accessed via NS access. NS access sites can only be accessed once and cannot use other access modes. If you want to use other access modes, please delete the existing NS access site first.\"\n   - **Terminate creation process**\n\n> **Important Notes**:\n> - NS access has exclusivity; a domain can only be accessed via NS once\n> - Domains accessed via NS cannot use CNAME or DNSPod hosting access\n> - Domains accessed via CNAME or DNSPod hosting cannot use NS access (but can continue using CNAME or DNSPod hosting to create sites with same name)\n\n### B2: Confirm Access Mode and Parameters\n\n**Call** `CreateZone`. User needs to provide:\n- **Site Domain**: Root domain to onboard\n- **Access Mode**: Display available options based on B1 detection results\n  - If DNSPod hosting conditions are met: **Prioritize recommending** DNSPod hosting access (dnspod), also provide CNAME access (partial) and NS access (full) options\n  - If conditions not met: Only provide CNAME access (partial) and NS access (full) options\n- **Acceleration Area** (Area): Optional values are mainland (Mainland China), overseas (Global excluding Mainland China), global (Global)\n  - **mainland (Mainland China)**: ⚠️ **Requires domain to have completed ICP filing with MIIT**\n  - **global (Global)**: ⚠️ **Requires domain to have completed ICP filing with MIIT**\n  - **overseas (Global excluding Mainland China)**: No filing requirement\n- **Alias Zone Name** (AliasZoneName): **Only needed when B1.5 pre-check returns domain conflict**\n  - Provided by user to distinguish sites with same name\n  - Format requirements: combination of numbers, English letters, `.`, `-`, `_`, within 200 characters\n\n> **Important Notes**:\n> - When selecting `mainland` or `global` area, must remind user to confirm domain has completed ICP filing, otherwise site will not be able to onboard and use normally.\n> - If B1.5 pre-check finds domain conflict, must require user to provide `AliasZoneName` parameter.\n\nSuggest passing PlanId directly when creating.\n\n> When not passing PlanId, site is in `init` status, need to bind later via BindZoneToPlan.\n>\n> **No Automatic Binding**: Whether passing PlanId via `CreateZone` or later calling `BindZoneToPlan`, **must** obtain user's explicit confirmation beforehand; never decide on your own which plan to bind.\n\n#### Exception Handling: Service Authorization Missing\n\n**Only when user selects DNSPod hosting access mode**, calling `CreateZone` may return error code `OperationDenied.DNSPodUnauthorizedRoleOperation`, indicating service authorization is missing.\n\n**Handling Steps**:\n\n1. **Automatically create service authorization**: Call CAM's `CreateServiceLinkedRole` interface\n   - `QCSServiceName`: `[\"DnspodaccesEO.TEO.cloud.tencent.com\"]`\n   - `Description`: `\"This role is a service-linked role for Tencent EdgeOne Platform (TEO). This role will query your domain status and related DNS records in DNSPod within the permission scope of associated policies, and help you quickly complete DNS modification to switch acceleration service to EO in one-click DNS modification scenarios\"`\n\n2. **Retry site creation**:\n   - If service authorization creation succeeds, retry calling `CreateZone` to create site\n   - If service authorization creation fails, enable fallback mode: prompt user to use NS access or CNAME access\n\n### Next Step for DNSPod Hosting Access\n\n> In DNSPod hosting access mode, EdgeOne will automatically complete ownership verification.\n\nAfter site creation succeeds:\n- Site will automatically complete ownership verification\n- Can directly go to [Scenario D: Add Acceleration Domain](#scenario-d-add-acceleration-domain)\n\n### Next Step for NS Access\n\nInform user that they need to modify DNS server to NameServers returned in response at domain registrar, then go to [Scenario C: Verify Ownership](#scenario-c-verify-ownership).\n\n### Next Step for CNAME Access\n\nInform user of two validation methods (choose one), get validation info from response:\n\n1. **DNS Validation**: Add TXT record in DNS\n2. **File Validation**: Place validation file in origin root directory\n\nAfter user confirms configuration complete, go to [Scenario C: Verify Ownership](#scenario-c-verify-ownership).\n\n### B3: No Domain Access\n\n**Applicable Scenarios**: User temporarily has no domain or only needs Layer 4 proxy and edge functions.\n\n**Call** `CreateZone`, parameters as follows:\n- `Type`: `noDomainAccess`\n- `ZoneName`: **Keep as empty string**\n- `Area`: **Keep as empty string**\n- `PlanId`: Pass confirmed plan ID\n\n> **Important Note**: In no-domain access mode, ZoneName and Area parameters must be kept empty, otherwise interface call will fail.\n\n**After creation succeeds**:\n- Site needs no ownership verification\n- Can directly use Layer 4 proxy and edge functions\n- Inform user: \"Site created successfully, you can now configure Layer 4 proxy or edge functions. If you need Layer 7 acceleration features, you can add acceleration domains anytime.\"\n\n**Follow-up Operations**:\n- Configure Layer 4 proxy: Refer to Layer 4 proxy related documentation\n- Configure edge functions: Refer to edge functions related documentation\n\n## Scenario C: Verify Ownership\n\n**Trigger**: User says \"verify site\", \"check DNS switch\", \"ownership verification\", or subsequent step after site creation.\n\n> User can choose to skip ownership verification and directly go to [Scenario D: Add Acceleration Domain](#scenario-d-add-acceleration-domain), verify later.\n\n### C1: Query Verification Status (DescribeIdentifications)\n\nBefore triggering verification, first call `DescribeIdentifications` to query current verification status.\n\n**Decision**:\n- If `Status` is `finished`, no need to verify again, go directly to next step\n- If `Status` is `pending`, inform user to configure DNS TXT record or file validation based on validation info in response\n\n### C2: Trigger Verification (VerifyOwnership)\n\nAfter user confirms DNS / file configuration complete, call `VerifyOwnership`.\n\n**NS Access Scenario**: Verify if DNS server switch succeeded. DNS switch usually takes 24-48 hours to take effect globally; if verification fails, suggest user retry later.\n\n**CNAME Access Scenario**: Verify if TXT record or file is configured correctly. If site passes ownership verification, adding domains later won't need verification again.\n\n## Scenario D: Add Acceleration Domain\n\n**Trigger**: User says \"add domain\", \"configure acceleration domain\", \"onboard subdomain\", or subsequent step after ownership verification completion (or skip).\n\n> **No-Domain Access Sites**: Sites created via no-domain access mode can also add Layer 7 acceleration domains anytime; after adding, can use complete Layer 7 acceleration features.\n\n### D0: Determine Target Site\n\n> If entering this scenario from a continuous flow of Scenario B/C, ZoneId is already known; you can skip this step and go directly to D1.\n\nWhen user directly triggers \"add domain\", you need to first determine which site to add the domain to.\n\n**Steps:**\n\n1. **Extract root domain**: Extract the root domain (e.g., `example.com`) from the acceleration domain provided by user (e.g., `www.example.com`).\n\n2. **Query matching sites**: Call `DescribeZones` with `zone-name` filter by root domain:\n   ```\n   --Filters '[{\"Name\":\"zone-name\",\"Values\":[\"example.com\"]}]'\n   ```\n\n3. **Filter and handle based on query results**:\n\n   First, filter out sites with `Status == \"initializing\"` — these sites are still initializing and must not be displayed.\n\n   Then handle the remaining sites:\n\n   - **No matching site** (or all filtered out): Prompt user that the root domain has not been onboarded to EdgeOne, guide to [Scenario A: Confirm Plan](#scenario-a-confirm-plan) to begin full onboarding process.\n\n   - **Only 1 site**: Display site info (ZoneId, alias, access mode, acceleration area, status) to user, proceed to D1 after confirmation.\n\n   - **Multiple sites** (same root domain may have multiple sites): **Must** display all matching sites for user selection; never automatically select the first one or any arbitrary one. Display info should include:\n     - **Site Alias** (AliasZoneName) — the most intuitive distinguishing identifier\n     - **ZoneId**\n     - **Access Mode** (Type: dnsPodAccess / partial / full)\n     - **Acceleration Area** (Area: mainland / overseas / global)\n     - **Status**: Determined using the [Site Status Determination Logic](#site-status-determination-logic)\n     - Suggest prioritizing sites with `Active` status\n\n   > **No Automatic Selection**: When multiple matching sites exist, **must** wait for user's explicit selection before continuing; never decide on your own.\n\n### D1: Collect Parameters\n\nNeed to confirm following information with user before calling:\n\n1. **Acceleration Domain** (DomainName): Subdomain to onboard, e.g., `www.example.com`\n2. **IPv6 Access** (IPv6Status): Whether to enable IPv6 access, values:\n   - `follow`: Follow site IPv6 configuration (default)\n   - `on`: Enable\n   - `off`: Disable\n3. **Origin Configuration** (OriginInfo): See [OriginInfo Data Structure](#origininfo-data-structure) below\n4. **Origin Protocol** (OriginProtocol, optional): FOLLOW (default) / HTTP / HTTPS\n5. **Origin Port** (optional): HTTP origin port (default 80) / HTTPS origin port (default 443)\n\n#### OriginInfo Data Structure\n\nOriginInfo is a required parameter for `CreateAccelerationDomain`, defining origin information.\n\n##### Required Fields\n\n| Field | Type | Description |\n|---|---|---|\n| **OriginType** | string | Origin type, see values below |\n| **Origin** | string | Origin address, fill in different values based on OriginType |\n\n##### OriginType Values and Origin Mapping\n\n| OriginType | Description | Origin Value |\n|---|---|---|\n| `IP_DOMAIN` | IPv4, IPv6, or domain type origin | IP address or domain, e.g., `1.1.1.1`, `origin.example.com` |\n| `COS` | Tencent Cloud COS object storage origin | COS bucket access domain |\n| `AWS_S3` | AWS S3 object storage origin | S3 bucket access domain |\n| `ORIGIN_GROUP` | Origin group type origin | Origin group ID; if referencing another site's origin group, format: `{OriginGroupID}@{ZoneID}` |\n| `VOD` | Cloud VOD | Cloud VOD application ID |\n| `LB` | Load balancer (whitelist only) | Load balancer instance ID; if referencing another site's LB, format: `{LBID}@{ZoneID}` |\n| `SPACE` | Origin offload (whitelist only) | Origin offload space ID |\n\n##### Optional Fields\n\n| Field | Type | Applicable Scenario | Description |\n|---|---|---|---|\n| **HostHeader** | string | Only when `OriginType = IP_DOMAIN` | Custom origin HOST header. **Do not pass this field** for other origin types, otherwise it will cause errors |\n| **PrivateAccess** | string | Only when `OriginType = COS` or `AWS_S3` | Whether to use private authentication: `on` / `off` (default off) |\n| **PrivateParameters** | list | Only when `PrivateAccess = on` | Private authentication parameter list |\n| **BackupOrigin** | string | Only when `OriginType = ORIGIN_GROUP` | Backup origin group ID (legacy feature, not recommended) |\n| **VodOriginScope** | string | Only when `OriginType = VOD` | Origin scope: `all` (default, all files in app) / `bucket` (specified bucket) |\n| **VodBucketId** | string | Only when `OriginType = VOD` and `VodOriginScope = bucket` | VOD bucket ID |\n\n##### Most Common Scenario Examples\n\n**IP/Domain origin** (most common):\n```json\n{\n  \"OriginType\": \"IP_DOMAIN\",\n  \"Origin\": \"1.1.1.1\"\n}\n```\n\n**COS origin (private access)**:\n```json\n{\n  \"OriginType\": \"COS\",\n  \"Origin\": \"bucket-xxx.cos.ap-guangzhou.myqcloud.com\",\n  \"PrivateAccess\": \"on\",\n  \"PrivateParameters\": [{\"Name\": \"SecretId\", \"Value\": \"xxx\"}, {\"Name\": \"SecretKey\", \"Value\": \"xxx\"}]\n}\n```\n\n**Origin group**:\n```json\n{\n  \"OriginType\": \"ORIGIN_GROUP\",\n  \"Origin\": \"og-testorigin\"\n}\n```\n\n### D2: Call CreateAccelerationDomain\n\n> **No Automatic Addition**: Adding acceleration domain will change online DNS configuration. **Must** complete parameter collection in D1 and obtain user's explicit confirmation before execution; never decide on your own.\n\nCall `CreateAccelerationDomain` after user confirmation.\n\n**Next Step**: Inform user that they need to add CNAME record in DNS, pointing domain to EdgeOne-assigned CNAME address (can query `Cname` field via `DescribeAccelerationDomains`).\n\n## Scenario E: Apply and Deploy HTTPS Certificate\n\n**Trigger**: After domain addition complete, user says \"configure HTTPS\", \"apply for certificate\", or as final step of onboarding process.\n\n> Complete certificate management (CNAME manual validation, deploy custom certificate, batch inspection, etc.) refer to [cert-manager.md](cert-manager.md).\n\n### E1: NS Access / DNSPod Hosting Access (Automatic Validation, One-Step Complete)\n\n> **Applicable Scenarios**: In NS access mode or DNSPod hosting access mode, EdgeOne can directly control DNS records, so can automatically complete certificate application and deployment.\n\n> **No Automatic Deployment**: Deploying certificate will directly affect domain's HTTPS service. **Must** inform user which domains will deploy which certificates, and wait for explicit confirmation before calling `ModifyHostsCertificate`.\n\n### E2: CNAME Access (Manual Validation)\n\nCNAME access needs to first apply for certificate, complete domain validation, then deploy; process is longer. Please refer to [cert-manager.md Scenario B2](cert-manager.md#b2-cname-access-manual-validation) for complete steps.\n\n## Scenario F: View Onboarding Status\n\n**Trigger**: User says \"check site status\", \"is domain onboarded\".\n\nCall `DescribeZones` to query target site status.\n\n> **Important**: When displaying site status, must use the [Site Status Determination Logic](#site-status-determination-logic) to determine and display the effective status. Sites with `Status == \"initializing\"` must be filtered out and not displayed to users.\n\n> Refer to [../api/zone-discovery.md](../api/zone-discovery.md) for more query methods.\n\nFile v1.1.1:references/api/api-discovery.md\n\n# EdgeOne API Discovery\n\nThe tccli service name for EdgeOne is **teo**.\nTypically, reference files already specify the API name to call — just look up the API documentation directly;\nuse fallback discovery only when references do not cover the scenario.\n\n---\n\n## Main Flow: Known API Name\n\n### 1. Read the API Documentation\n\nGet parameter descriptions and request examples for a specific API:\n\n```sh\ncurl -s https://cloudcache.tencentcs.com/capi/refs/service/teo/action/CreatePurgeTask.md\n```\n\n### 2. Read Data Structures\n\nComplex data structures referenced in the API documentation can be further examined:\n\n```sh\ncurl -s https://cloudcache.tencentcs.com/capi/refs/service/teo/model/Task.md\n```\n\n---\n\n## Fallback: Not Sure Which API to Call\n\nWhen references do not specify an API, or you need to explore uncovered scenarios, search in the following order:\n\n### 1. Search the API List\n\nSearch for keywords in the API list (the Action name is the second argument after `tccli teo`):\n\n```sh\ncurl -s https://cloudcache.tencentcs.com/capi/refs/service/teo/actions.md \\\n  | grep -i \"purge\\|cache\"\n```\n\n### 2. Search Best Practices\n\nCheck if there are best practices matching the current scenario (with complete call examples):\n\n```sh\ncurl -s https://cloudcache.tencentcs.com/capi/refs/service/teo/practices.md \\\n  | grep -i \"purge\\|refresh\"\n```\n\n### 3. Read Best Practice Details\n\n```sh\ncurl -s https://cloudcache.tencentcs.com/capi/refs/service/teo/practice/practice-53.md\n```\n\n---\n\nFile v1.1.1:references/api/auth.md\n\n# Configure TCCLI Credentials\n\n## Login Method\n\nFirst, run the following command to verify the current login status:\n\n```sh\ntccli cvm DescribeRegions --request-client \"tencent-edgeone-skill/1.1.0 module/api\" 2>&1; echo \"EXIT_CODE:$?\"\n```\n\n- If a normal result is returned, you are already logged in — no need to log in again.\n- If it shows `secretId is invalid` or other authentication errors, you are not logged in and need to continue with the login command below.\n\nBrowser-based authorization login is recommended — no need to manually enter SecretId/SecretKey, credentials are automatically saved locally:\n\n```sh\ntccli auth login\n```\n\nAfter execution, TCCLI will start a temporary port on your machine and print an OAuth authorization link (it usually also opens automatically in the default browser). Once the user completes login and authorization in the browser, TCCLI receives the callback, writes the credentials, and exits.\n\n- If the browser does not open automatically, copy the link printed in the terminal and open it manually in a browser.\n- Upon success, it will display: \"Login successful, credentials have been written to: ...\"\n\n---\n\n## Agent Operating Guidelines\n\n**Determining whether login is needed:**\n\n1. First run `tccli cvm DescribeRegions`.\n2. If a **reasonable success result** is returned, consider the user logged in and proceed with subsequent operations.\n3. If an error is returned or the command cannot execute, you must first run `tccli auth login`.\n4. Never ask the user for `SecretId` / `SecretKey`, and do not execute commands that might expose credential contents (especially `tccli configure list`).\n\n\n> ⚠️ The Agent must not assume TCCLI is usable based solely on the user's verbal statement or potentially stale credential files on the machine.\n\n**When running `tccli auth login`:**\n\n- This command will **block** until the user completes browser login (or it times out).\n- The Agent should clearly inform the user: \"Please open the authorization link shown in the terminal/tool output and complete login in the browser; the command will end automatically once done.\"\n\n---\n\n## Multi-Account & Logout\n\n| Operation | Command |\n|------|------|\n| Login default account | `tccli auth login` |\n| Login specific account | `tccli auth login --profile user1` |\n| Logout default account | `tccli auth logout` |\n| Logout specific account | `tccli auth logout --profile user1` |\n\nCredential file notes:\n- Default account credentials are saved in `default.credential`\n- Specific account credentials are saved in `<profile-name>.credential` (e.g., `user1.credential`)\n\n## Security Reminder\n\n> Using `tccli configure` to manually enter SecretId / SecretKey is **not recommended**. Manually configured keys are stored in plaintext locally and risk being leaked. Always use the `tccli auth login` browser authorization method.\n\nFile v1.1.1:references/api/dnspod-integration.md\n\n# DNSPod Integration API Reference\n\nEdgeOne supports DNSPod hosting access mode, enabling one-click domain onboarding and automated configuration. This document explains how to call related APIs.\n\n## Query Domain Hosting Status\n\n### DescribeDomain (DNSPod)\n\n**Purpose**: Query whether domain is hosted in DNSPod and if hosting status meets EdgeOne access conditions.\n\n**Invocation Example**:\n\n```bash\ntccli dnspod DescribeDomain --Domain \"example.com\" --request-client \"tencent-edgeone-skill/1.1.0 module/api\"\n```\n\n**Key Response Fields**:\n\n```json\n{\n  \"DomainInfo\": {\n    \"Domain\": \"example.com\",\n    \"DomainId\": 12345678,\n    \"Status\": \"ENABLE\",        // Domain status: ENABLE(normal), PAUSE(paused), SPAM(blocked)\n    \"DnsStatus\": \"\",           // DNS status: empty string(normal), \"dnserror\"(abnormal)\n    \"Grade\": \"DP_Pro\",         // Plan level\n    \"DnspodNsList\": [          // DNSPod's NS list\n      \"ns1.dnspod.net\",\n      \"ns2.dnspod.net\"\n    ],\n    \"ActualNsList\": [          // Actual NS used by domain\n      \"ns1.dnspod.net\",\n      \"ns2.dnspod.net\"\n    ]\n  }\n}\n```\n\n**EdgeOne Access Condition Determination**:\n\nDomain can use DNSPod hosting access when meeting all of the following conditions:\n\n1. ✅ Domain exists (interface call succeeds)\n2. ✅ `Status` field is `\"ENABLE\"` or `\"LOCK\"`\n3. ✅ `DnsStatus` field is empty string `\"\"`\n\n**Common Error Handling**:\n\n| Error Code | Description | Handling Method |\n|--------|------|----------|\n| `ResourceNotFound.NoDataOfDomain` | Domain doesn't exist in DNSPod | Don't display DNSPod hosting access option |\n| `OperationDenied.DNSPodUnauthorizedRoleOperation` | Missing service authorization | Try to automatically create service authorization role |\n| `UnauthorizedOperation` | User lacks DNSPod interface permission | Don't display DNSPod hosting access option |\n\n## Create Service-Linked Role\n\n### CreateServiceLinkedRole (CAM)\n\n**Purpose**: Create service authorization role for EdgeOne to access DNSPod for user.\n\n**Trigger Scenario**: When calling `DescribeDomain` interface returns `OperationDenied.DNSPodUnauthorizedRoleOperation` error.\n\n**Invocation Example**:\n\n```bash\ntccli cam CreateServiceLinkedRole \\\n  --QCSServiceName '[\"DnspodaccesEO.TEO.cloud.tencent.com\"]' \\\n  --Description \"This role is a service-linked role for Tencent EdgeOne Platform (TEO). This role will query your domain status and related DNS records in DNSPod within the permission scope of associated policies, and help you quickly complete DNS modification to switch acceleration service to EO in one-click DNS modification scenarios\" \\\n  --request-client \"tencent-edgeone-skill/1.1.0 module/api\"\n```\n\n**Response Example**:\n\n```json\n{\n  \"RoleId\": \"4611686018428516331\",\n  \"RequestId\": \"abcd1234-5678-90ef-ghij-klmnopqrstuv\"\n}\n```\n\n**Follow-up Actions**:\n\n- ✅ If creation succeeds: Retry calling `DescribeDomain` to detect domain status\n- ❌ If creation fails: Enable fallback mode, don't display DNSPod hosting access option\n\n## DNSPod Hosting Access Process\n\n### Complete Invocation Flow\n\n```mermaid\ngraph TD\n    A[Start Access] --> B[Call DescribeDomain]\n    B --> C{Domain Exists?}\n    C -->|No| D[Don't Display DNSPod Hosting Access]\n    C -->|Yes| E{Status and DnsStatus Meet Conditions?}\n    E -->|No| D\n    E -->|Yes| F[Display DNSPod Hosting Access as Preferred]\n    B --> G{Error Code is Authorization Error?}\n    G -->|Yes| H[Call CreateServiceLinkedRole]\n    H --> I{Creation Succeeds?}\n    I -->|Yes| B\n    I -->|No| D\n    G -->|No| J{Other Permission Errors?}\n    J -->|Yes| D\n    F --> K[User Selects DNSPod Hosting Access]\n    K --> L[Call CreateZone Type=dnspod]\n    L --> M[Automatically Complete Ownership Verification]\n    M --> N[Add Acceleration Domain]\n```\n\n### Access Mode Parameters\n\nWhen calling `CreateZone`, optional values for `Type` parameter:\n\n- `dnspod`: DNSPod hosting access\n- `full`: NS access\n- `partial`: CNAME access\n\n**Recommendation Strategy**:\n\n1. Prioritize detecting if DNSPod hosting access conditions are met\n2. If met, display `dnspod` as **preferred recommendation** to user\n3. Always provide `full` and `partial` as alternative options\n\n## Best Practices\n\n### 1. Silent Detection, Smart Recommendation\n\n```python\n# Pseudo-code example\ndef get_available_access_types(domain):\n    access_types = []\n    \n    # Try to detect DNSPod hosting status\n    try:\n        response = dnspod.DescribeDomain(Domain=domain)\n        domain_info = response['DomainInfo']\n        \n        # Determine if conditions are met\n        if (domain_info['Status'] in ['ENABLE', 'LOCK'] and \n            domain_info['DnsStatus'] == ''):\n            access_types.append({\n                'type': 'dnspod',\n                'name': 'DNSPod Hosting Access',\n                'recommended': True,\n                'description': 'No manual configuration needed, automatically completes validation'\n            })\n    \n    except DNSPodUnauthorizedRoleOperation:\n        # Try automatic authorization\n        try:\n            cam.CreateServiceLinkedRole(...)\n            # Retry detection\n            return get_available_access_types(domain)\n        except:\n            pass  # Authorization failed, use fallback plan\n    \n    except:\n        pass  # Other errors, use fallback plan\n    \n    # Fallback: Always provide NS and CNAME access\n    access_types.extend([\n        {'type': 'full', 'name': 'NS Access'},\n        {'type': 'partial', 'name': 'CNAME Access'}\n    ])\n    \n    return access_types\n```\n\n### 2. User Experience Optimization\n\n**Suggested Wording When Displaying to User**:\n\n✅ **When DNSPod Hosting Conditions Are Met**:\n\n> Detected that your domain `example.com` is hosted in DNSPod. Recommend using **DNSPod Hosting Access** mode, which can automatically complete validation and configuration without manual DNS operations.\n> \n> You can also choose other access modes:\n> - NS Access: Need to modify domain's NS record\n> - CNAME Access: Need to add TXT record to verify ownership\n\n❌ **When DNSPod Hosting Conditions Are Not Met**:\n\n> Please select access mode:\n> - NS Access: EdgeOne fully takes over DNS resolution\n> - CNAME Access: Only configure CNAME record, NS unchanged\n\n### 3. Error Handling Suggestions\n\n| Scenario | User Prompt | Technical Handling |\n|------|----------|----------|\n| Domain Not in DNSPod | No prompt, directly provide NS/CNAME options | Handle silently |\n| Missing Service Authorization | \"Configuring service authorization for you...\" | Automatically call CreateServiceLinkedRole |\n| Authorization Creation Failed | No prompt, directly provide NS/CNAME options | Silently fall back to fallback plan |\n| Domain Status Abnormal | No prompt, directly provide NS/CNAME options | Handle silently |\n\n## Reference Materials\n\n- [DNSPod API Documentation](https://cloud.tencent.com/document/product/1427)\n- [CAM Service-Linked Roles](https://cloud.tencent.com/document/product/598/19388)\n- [EdgeOne CreateZone Interface](https://cloud.tencent.com/document/product/1552/80719)\n\nArchive v1.1.0: 23 files, 68350 bytes\n\nFiles: references/acceleration/cache-purge.md (12388b), references/acceleration/cert-manager.md (9616b), references/acceleration/README.md (843b), references/acceleration/zone-onboarding.md (25281b), references/api/api-discovery.md (1480b), references/api/auth.md (2857b), references/api/dnspod-integration.md (6977b), references/api/install.md (1921b), references/api/README.md (4764b), references/api/zone-discovery.md (3477b), references/observability/eo-log-analyzer.md (14009b), references/observability/eo-log-downloader.md (6385b), references/observability/eo-origin-health-check.md (18870b), references/observability/eo-traffic-daily-report.md (24475b), references/observability/README.md (2766b), references/security/domain-blacklist-inspector.md (5013b), references/security/ip-threat-blacklist.md (8529b), references/security/README.md (2654b), references/security/security-template-audit.md (4637b), references/security/security-weekly-report.md (4979b), skill-card.md (3085b), SKILL.md (3874b), _meta.json (140b)\n\nFile v1.1.0:SKILL.md\n\n---\nname: tencent-edgeone-skill\ndescription: A comprehensive skill for Tencent EdgeOne (Edge Security & Acceleration Platform), covering edge acceleration (DNS, certificates, caching, rule engine, L4 proxy, load balancing), edge security (DDoS protection, Web protection, Bot management), edge media (real-time video / image processing), edge development (Edge Functions, EdgeOne Pages), and more. Use this skill whenever a user mentions any EdgeOne / EO-related configuration, operations, querying, or troubleshooting needs.\nversion: 1.1.0\nmetadata:\n  openclaw:\n    requires:\n      bins:\n        - tccli\n        - gunzip\n      anyBins:\n        - curl\n        - wget\n        - jq\n        - python3\n      config:\n        - ~/.tccli/default.credential\n    homepage: https://edgeone.ai\n---\n\n# Tencent EdgeOne Skill\n\nA comprehensive Tencent EdgeOne skill that routes user requests to the appropriate module and loads the corresponding reference document.\n\nKnowledge about EdgeOne APIs, configuration options, limits, and pricing may be outdated.\n**Prefer retrieval over pre-trained knowledge** — the reference files in this skill are only a starting point.\n\n> All tasks **must be completed by calling APIs**.\n> See `references/api/README.md` for API calling conventions, environment checks, etc. **(must be read before starting any task)**.\n\n## Security Red Lines\n\n- **Write operations require user confirmation**: All write operations (Create\\* / Modify\\* / Bind\\* / Delete\\* / Apply\\*, etc.) **must** clearly explain the action and its impact to the user before execution, and wait for user confirmation before calling the API.\n- **Never** ask the user for SecretId / SecretKey\n- **Refuse** any operation that might print credentials\n\n## Interaction & Execution Guidelines\n\n- **Use structured interaction tools**: When asking questions, requesting choices, or confirming operations, if the current environment provides `ask_followup_question` or similar structured interaction tools, you **must** prefer using them (instead of plain-text questions) so that the user can directly click options, reducing ambiguity and improving interaction efficiency. **Do not omit candidate options** — if there are too many to list in full, **must** state the total number first, show the most relevant items, and keep an \"Other (please enter)\" option as the last choice.\n- **Prefer scripts for bulk / repetitive tasks**: For tasks involving large datasets or repetitive operations (batch purge, batch query, loop operations, etc.), prefer writing a script to execute everything at once rather than calling APIs one by one manually.\n\n## Module Entry Points\n\nMatch the user's request to the appropriate module, load its entry document, and follow the instructions.\n\n| Module | Entry | Description |\n|---|---|---|\n| API | `references/api/README.md` | Calling conventions, tool installation, credential configuration, API discovery, zone & domain discovery (ZoneId lookup) |\n| Acceleration | `references/acceleration/README.md` | Site onboarding, cache purge / prefetch, certificate management |\n| Security | `references/security/README.md` | Security policy template audit, blocklist IP group query, security report |\n| Observability | `references/observability/README.md` | Traffic Daily Report Generation, Origin Health Inspection, Offline Log Download and Analysis |\n\n## Fallback Retrieval\n\nIf the user's request **cannot match any module above**, or the module's reference files do not cover the scenario, fall back in the following order:\n1. First read `references/api/api-discovery.md` and try to find the relevant API through API discovery.\n2. If still unresolved, search the [Tencent EdgeOne product documentation](https://edgeone.ai/document) for the latest information.\n\nWhen reference files conflict with official documentation, **the official documentation takes precedence**.\n\nFile v1.1.0:references/acceleration/README.md\n\n# EdgeOne Site Acceleration Reference\n\n> **Telemetry note:** You are now in module **`acceleration`**. Every `tccli` call you make from this entry must carry `--request-client \"tencent-edgeone-skill/1.1.0 module/acceleration\"`.\n\nConfiguration and operational guidance for site onboarding, domain management, cache purge/prefetch, and HTTPS certificates.\n\n## Files in This Directory\n\n| File | Risk Level | Trigger Scenarios (User says...) |\n|---|---|---|\n| `zone-onboarding.md` | Medium-High | \"Onboard example.com to EO\" \"Create a new site\" \"Apply for free certificate after onboarding\" |\n| `cache-purge.md` | Medium | \"Purge all cache under /static/\" \"Prefetch these URLs\" \"Check purge task status\" |\n| `cert-manager.md` | Medium | \"Renew certificate that's expiring soon\" \"Bind new certificate to these domains\" \"Check certificate status\" |\n\nFile v1.1.0:references/api/README.md\n\n# EdgeOne API Reference\n\n> **Telemetry note:** You are now in module **`api`**. Every `tccli` call you make from this entry must carry `--request-client \"tencent-edgeone-skill/1.1.0 module/api\"`. See \"Telemetry — RequestClient\" below.\n\nEdgeOne (Edge Security Acceleration Platform) is managed through Tencent Cloud API. Currently uses **tccli** (Tencent Cloud CLI) as the calling tool, with service name **teo**.\n\n## Telemetry — RequestClient (mandatory, best-effort)\n\nEvery `tccli` call you issue while working in this skill — the connectivity probe, `teo` actions, and `dnspod` / `cam` integration calls alike — must carry the `--request-client` flag:\n\n```sh\ntccli <service> <Action> --request-client \"tencent-edgeone-skill/1.1.0 module/<module>\" [other args]\n```\n\n- `<module>` — the entry README you're working from (e.g. `api`, `acceleration`...), or `other` if none fits.\n- Pass the flag per call, so each call carries its own module.\n\n> **Best-effort principle:** telemetry failure must never block or break the user's real task.\n\n## Files in This Directory\n\n| File | Applicable Scenarios |\n|---|---|\n| `install.md` | First-time setup: install tccli (pipx / Homebrew), prepare Python environment |\n| `auth.md` | tccli is installed but missing credentials — browser OAuth login, logout, or multi-account management |\n| `api-discovery.md` | Find API endpoints — search best practices, API lists, and documentation via cloudcache |\n| `zone-discovery.md` | Get zone / domain info: ZoneId lookup, reverse domain lookup, pagination handling |\n| `dnspod-integration.md` | DNSPod hosting access: detect domain hosting status, service authorization, access process |\n\n## Overview\n\n**tccli** is Tencent Cloud's official CLI tool, supporting all cloud API calls.\n\n**Key elements:**\n- **Calling format** — `tccli teo <Action> --request-client \"tencent-edgeone-skill/1.1.0 module/<module>\" [--param value ...]`\n- **Auto credentials** — Browser OAuth authorization is recommended, see `auth.md`\n- **API discovery** — Search best practices, API lists, and documentation online via cloudcache\n\n**Calling conventions:**\n- **Check documentation before calling**: Except for verifying tool availability, you **must** consult the API documentation via `api-discovery.md` before calling any API to confirm the action name, required parameters, and data structures. **Never guess parameters from memory.**\n- If a field's type is a struct, you **must** continue looking up the full field definitions of that struct, recursively until all nested structs have been identified — do not skip or guess.\n\n| Item | Description |\n|---|---|\n| Invocation Form | `tccli teo <Action> --request-client \"tencent-edgeone-skill/1.1.0 module/<module>\" [--param value ...]` |\n| Region | No `--region` by default; add `--region <region>` if user explicitly specifies region |\n| Parameter Format | Non-simple types must be standard JSON |\n| Serial Invocation | tccli has config file competition issues with parallel calls, please call one by one |\n| Error Capture | Every tccli command **must** end with `2>&1; echo \"EXIT_CODE:$?\"`, otherwise stderr will be swallowed and you won't see specific error messages |\n\n## Quick Start\n\n**Before first API call in each session**, execute tool check first:\n\n```sh\ntccli cvm DescribeRegions --request-client \"tencent-edgeone-skill/1.1.0 module/api\" 2>&1; echo \"EXIT_CODE:$?\"\n```\n\nDetermine next step based on result:\n\n| Result | Meaning | Next Step |\n|---|---|---|\n| Normal JSON response | Tool is installed, credentials are valid | Proceed with API operations |\n| `command not found` / `not found` | tccli is not installed | Read `install.md` to install |\n| `secretId is invalid` or auth error | tccli is installed but missing credentials | Read `auth.md` to configure credentials |\n| `Unknown options: --request-client` | tccli too old for the telemetry flag | Drop the flag and re-run now (best-effort); then ask the user whether to update tccli to the latest build (see `install.md` → \"Update tccli\") |\n\n## Fallback Retrieval Sources\n\nWhen files in this directory don't cover content, or need to confirm latest values / limits, retrieve via the following sources.\nWhen reference files conflict with official documentation, **official documentation takes precedence**.\n\n| Source | Retrieval Method | Used For |\n|---|---|---|\n| EdgeOne API docs | [edgeone.ai/document/50454](https://edgeone.ai/document/50454) | API parameters, request examples, data structures |\n| teo API discovery | cloudcache commands in `api-discovery.md` | Dynamically find APIs, best practices |\n| Tencent Cloud CLI docs | [github.com/TencentCloud/tencentcloud-cli](https://github.com/TencentCloud/tencentcloud-cli) | tccli installation, configuration, usage |\n\nFile v1.1.0:references/observability/README.md\n\n# EdgeOne Observability Reference\n\n> **Telemetry note:** You are now in module **`observability`**. Every `tccli` call you make from this entry must carry `--request-client \"tencent-edgeone-skill/1.1.0 module/observability\"`.\n\nOperational guides for traffic daily report generation, origin health inspection, offline log download, and log analysis.\n\n## Quick Decision Tree\n\n```\nWhat does the user want to do?\n│\n├─ \"Generate yesterday's traffic daily report\"\n│  \"Show me the bandwidth peak over the last 24 hours\"\n│  └─ → `eo-traffic-daily-report.md`  🟢 Low Risk · Auto-collect L7/L4 data and generate a Markdown daily report\n│\n├─ \"Check the origin status for example.com\"\n│  \"Is the origin healthy?\" \"Is it a CDN issue or an origin issue?\"\n│  └─ → `eo-origin-health-check.md`  🟢 Low Risk · Origin status code distribution + health ratio + quick root cause analysis\n│\n├─ \"Download the logs for example.com from yesterday afternoon\"\n│  \"Download the last 6 hours of L4 logs\"\n│  └─ → `eo-log-downloader.md`  🟢 Low Risk · Natural language driven offline log download link retrieval\n│\n├─ \"Analyze the logs — too many 502 errors\"\n│  \"Which URIs have the most abnormal requests?\"\n│  \"Show me per-URL download traffic breakdown\"\n│  └─ → `eo-log-analyzer.md`  🟢 Low Risk · Log download + local parsing + pattern recognition + fault inference + traffic aggregation\n│\n└─ Not sure which API to call\n   └─ → `../api/api-discovery.md`\n```\n\n## Prerequisites\n\nAll operations require API calls via tccli. Before first use, complete the following:\n\n1. **Tool Setup** — Read `../api/README.md` to install tccli and configure credentials\n2. **Get ZoneId** — Read `../api/zone-discovery.md` to obtain the zone ID\n\n## Files in This Directory\n\n| File | Risk Level | Core Trigger Scenario |\n|---|---|---|\n| `eo-traffic-daily-report.md` | 🟢 Low Risk | Query L7/L4 traffic trends daily and generate a Markdown report with bandwidth peak, request volume, and Top domains/regions |\n| `eo-origin-health-check.md` | 🟢 Low Risk | Query origin status code distribution and origin health ratio for quick origin fault root cause analysis |\n| `eo-log-downloader.md` | 🟢 Low Risk | Describe time range and domain in natural language to automatically retrieve offline log download links |\n| `eo-log-analyzer.md` | 🟢 Low Risk | Automatically download and parse logs locally, extract anomaly details, provide pattern recognition conclusions with fault inference, or aggregate traffic by domain/URL |\n\n## Reference Links\n\n- [EdgeOne Product Documentation](https://edgeone.ai/document/56978)\n- [EdgeOne API Documentation](https://edgeone.ai/document/50454)\n- API Usage Guide: `../api/README.md`\n\nFile v1.1.0:references/security/README.md\n\n# EdgeOne Security Protection Reference\n\n> **Telemetry note:** You are now in module **`security`**. Every `tccli` call you make from this entry must carry `--request-client \"tencent-edgeone-skill/1.1.0 module/security\"`.\n\nConfiguration and operations guide for security policy configuration snapshots, template coverage audits, and domain IP group blocklist identification.\n\n## Quick Decision Tree\n\n```\nWhat does the user want to do?\n│\n├─ \"Generate a security status report for this week\"\n│  \"Check the current security configuration\"\n│  └─ → `security-weekly-report.md`  🟢 Low risk · Sequential data collection, output conclusions first with concise snapshot\n│\n├─ \"Which domains don't have a security template\"\n│  \"Help me check template coverage\"\n│  └─ → `security-template-audit.md`  🟢 Low risk · List unbound domains, prompt for manual confirmation\n│\n├─ \"Check which IP group in example.com's security policy is a blocklist\"\n│  \"Which IP group blocks traffic for this domain\"\n│  └─ → `domain-blacklist-inspector.md`  🟢 Low risk · Read-only query, identify blocklist IP groups\n│\n├─ \"Help me analyze recent attack IP concentration\"\n│  \"Block these IPs\" \"IP ban\"\n│  └─ → `ip-threat-blacklist.md`  🔴 High risk · Mandatory Diff display + double confirmation before write operations, only allowed to write to designated blocklist group\n│\n└─ Not sure which API to call\n   └─ → `../api/api-discovery.md`\n```\n\n## Prerequisites\n\nAll operations require calling APIs via tccli. Before first use, complete the following:\n\n1. **Tool check** — Read `../api/README.md` to complete tccli installation and credential configuration\n2. **Get ZoneId** — Read `../api/zone-discovery.md` to obtain the zone ID\n\n## Files in This Directory\n\n| File | Risk Level | Core Trigger Scenario |\n|---|---|---|\n| `security-weekly-report.md` | 🟢 Low risk | Periodically generate security configuration snapshots to detect abnormal policy changes |\n| `security-template-audit.md` | 🟢 Low risk | Audit security policy template coverage, find domains without bound templates |\n| `domain-blacklist-inspector.md` | 🟢 Low risk | Query security policies associated with a specific domain, identify IP groups serving as blocklists |\n| `ip-threat-blacklist.md` | 🔴 High risk | Analyze L7 high-concentration threat IPs, execute IP blocklist banning (write operations require double confirmation) |\n\n## Reference Links\n\n- [EdgeOne Product Documentation](https://edgeone.ai/document)\n- [EdgeOne API Documentation](https://edgeone.ai/document/50454)\n- API Calling Guide: `../api/README.md`\n\nFile v1.1.0:_meta.json\n\n{\n  \"ownerId\": \"kn77cw5hbmapf54rv89jdqwp7x835m4k\",\n  \"slug\": \"tencent-edgeone-skill\",\n  \"version\": \"1.1.0\",\n  \"publishedAt\": 1780471332265\n}\n\nFile v1.1.0:references/acceleration/cache-purge.md\n\n# Cache Purge and Prefetch\n\nManage EdgeOne node cache: query quotas, purge cache (URL / Directory / Host / All / Cache Tag), prefetch URLs, and check task progress. Supports batch URL input from files or paste.\n\n## Core Interaction Guidelines\n\n1. **Site Selection and Confirmation**: Before executing any cache operation, users must first confirm the target site (see Scenario 0)\n2. **Check Quota Before Submission**: Before executing CreatePurgeTask / CreatePrefetchTask, call DescribeContentQuota to display remaining quota; warn users if insufficient\n3. **Batch URL Input**: Support users to input URLs in batch from files or by pasting (see Scenario E)\n4. **Poll Task Progress**: Actively query progress after task submission until completion or timeout\n\n## Scenario 0: Select Site\n\n**Trigger**: Before users request cache purge or URL prefetch, the target site must be confirmed first.\n\n**Steps**:\n\n1. **Call DescribeZones to query site list**\n   - **Important**: Filter out sites with `Status` as `initializing` (these sites are still initializing and haven't completed creation)\n   - **Critical**: **Must use pagination** to retrieve all sites:\n     - Set `Limit=100` (maximum value)\n     - Set `Offset=0` initially, increment by 100 each iteration\n     - Loop until `Offset + Limit >= TotalCount`\n     - Merge all paginated results\n   - Refer to [zone-discovery.md](../api/zone-discovery.md) for detailed pagination implementation\n   - Only display available sites\n\n2. **Determine the number of sites**:\n   \n   **a) Only one site**\n   - Directly use this site without user selection\n   - Continue to subsequent operations\n\n   **b) Multiple sites**\n   - List all available sites, including:\n     - Site domain name (ZoneName)\n     - Alias Zone Name (AliasZoneName, if any)\n     - Site ID (ZoneId)\n     - Access mode (Type)\n   - Guide users to select the site to operate on\n\n   **c) No available sites**\n   - Prompt user: \"No available sites under current account, please create a site first\"\n   - Terminate operation\n\n3. **Handle sites with same name**:\n   - If multiple sites with the same name exist (same ZoneName), they must be distinguished by `AliasZoneName` (Alias Zone Name identifier)\n   - Display format: `Site domain (identifier)` or `Site domain [identifier]`\n   - Example: `example.com (prod)` and `example.com (test)`\n\n4. **Get Site ID**:\n   - After user confirms the site, record the site's `ZoneId`\n   - All subsequent API calls use this `ZoneId`\n\n> **Important Notes**:\n> - Site selection is a prerequisite for all cache operations and cannot be skipped\n> - Alias Zone Name (AliasZoneName) is used to distinguish sites with the same name created with different access modes (CNAME, DNSPod hosting)\n> - If the user explicitly specifies the site domain or identifier in the request, you can directly use this information to query the corresponding site\n\n## Scenario A: Query Quota\n\n**Trigger**: User says \"how many more can I purge\", \"check quota\", \"how much prefetch quota left\".\n\n> **Prerequisite** (optional): If user hasn't specified a site, complete [Scenario 0: Select Site](#scenario-0-select-site) first\n\nCall `DescribeContentQuota`, passing parameters:\n- `ZoneId`: Site ID (optional, query account-level quota if not provided)\n\n**Output suggestion**: Display quota usage for each type in a table, marking types with less than 10% remaining.\n\n## Scenario B: Cache Purge\n\n**Trigger**: User says \"purge cache\", \"clear CDN cache\", \"purge URL\", \"purge directory\", \"purge entire site\".\n\n> **Prerequisites**:\n> 1. Complete [Scenario 0: Select Site](#scenario-0-select-site) to confirm the site to operate on\n> 2. Call DescribeAccelerationDomains to confirm available acceleration domains under the site\n> 3. Call DescribeContentQuota (Scenario A) to display remaining quota; warn user if insufficient for the corresponding type\n\n### B1: Confirm Purge Type and Method\n\nBefore executing purge, **must** have users confirm the following information:\n\n#### 1. Purge Type\n\n| Type | Parameter Value | Description | Impact Scope |\n|------|--------|------|----------|\n| **URL Purge** | `purge_url` | Purge specified URLs | Exactly matched URLs |\n| **Directory Purge** | `purge_prefix` | Purge all resources under specified directory | All files under directory and subdirectories |\n| **Hostname Purge** | `purge_host` | Purge all resources under specified domain | All cache of the entire acceleration domain |\n| **Full Site Purge** | `purge_all` | Purge all resources under the site | ⚠️ All cache on all nodes of the site |\n| **Cache Tag Purge** | `purge_cache_tag` | Purge by cache tag | All cache with specified tags |\n\n#### 2. Purge Method\n\nPurge method is **only valid for the following three purge types**:\n- ✅ **Directory Purge** (`purge_prefix`)\n- ✅ **Hostname Purge** (`purge_host`)\n- ✅ **Full Site Purge** (`purge_all`)\n\nOther purge types (URL purge, Cache Tag purge) do not support the purge method parameter.\n\n**Available Values**:\n\n| Method | Parameter Value | Description | Recommended Scenario |\n|------|--------|------|----------|\n| **Invalidate Cache** | `invalidate` | Mark cache as expired, validate with origin on next request | Default method, less pressure on origin |\n| **Delete Cache** | `delete` | Directly delete cache, always fetch from origin on next request | Emergency updates, forced refresh scenarios |\n\n> **Important Notes**:\n> - The `invalidate` method keeps the cache but marks it as expired; on the next request, it validates with the origin through mechanisms like If-Modified-Since, and can continue using cache if content hasn't changed\n> - The `delete` method directly deletes the cache; all subsequent requests will fetch from origin, which will increase origin load in a short time\n\n#### 3. User Confirmation Process\n\n**Prompt user**:\n1. Display purge types and their impact scope\n2. If selecting `purge_prefix`, `purge_host`, or `purge_all`, ask about purge method\n3. If selecting `purge_all` (full site purge), **must** specially warn:\n   > ⚠️ **Full site purge is a high-impact operation**: It will clear all node cache of this site; in a short time, a large number of requests will fetch from origin, which may cause origin pressure to surge. Please confirm whether to continue?\n\n4. Wait for user's explicit confirmation before executing\n\n> **No automatic purge**: Cache purge will invalidate node cache; subsequent requests will fetch the latest content from origin, which may increase origin load. **Must** explain the purge type and impact scope to users and wait for explicit confirmation before execution.\n\n### B2: Execute Purge\n\n**Call** `CreatePurgeTask`, passing parameters:\n- `ZoneId`: Site ID (from Scenario 0)\n- `Type`: Purge type\n- `Method`: Purge method (only valid when Type is `purge_prefix`, `purge_host`, or `purge_all`)\n- `Targets`: List of URLs / directories / domains to purge\n\n**Follow-up**: Inform user that the task has been submitted and provide JobId. If confirmation of execution result is needed, go to [Scenario D](#scenario-d-query-task-progress).\n\n## Scenario C: URL Prefetch\n\n**Trigger**: User says \"prefetch URL\", \"prefetch cache\", \"prefetch\", \"preload resources\".\n\n> **Prerequisites**:\n> 1. Complete [Scenario 0: Select Site](#scenario-0-select-site) to confirm the site to operate on\n> 2. Call DescribeContentQuota (Scenario A) to display remaining `prefetch_url` quota\n> 3. (Optional) Call DescribePrefetchOriginLimit to query origin rate limit for the target domain\n\nURL prefetch actively fetches resources from origin to edge node cache, suitable for preloading hot resources before major promotions or version releases.\n\n### C1: URL Format Check\n\nBefore executing prefetch, **must** check if URL format meets requirements:\n\n**✅ Supported URL Formats**:\n- Complete HTTP/HTTPS URL: `https://example.com/path/to/file.jpg`\n- URL with query parameters: `https://example.com/api/data?id=123&type=json`\n- Specific file path: `https://cdn.example.com/images/banner.png`\n\n**❌ Unsupported URL Formats**:\n- ⚠️ **URLs with wildcards**: `https://example.com/path/*` or `https://example.com/*.jpg`\n- Directory paths: `https://example.com/path/` (for directory prefetch, use multiple specific file URLs)\n- Incomplete URLs: `example.com/path` (missing protocol)\n\n**Check Rules**:\n1. URL must start with `http://` or `https://`\n2. URL cannot contain wildcards `*` or `?` (except `?` in query parameters)\n3. It's recommended that each URL points to a specific file resource\n\n**Processing Flow**:\n```\nIterate through user-provided URL list\n  ├─ Check if contains wildcards (* ?)\n  │  ├─ Contains → Prompt user: \"Prefetch doesn't support wildcard URLs, please provide specific file URLs\"\n  │  └─ Doesn't contain → Continue\n  ├─ Check protocol\n  │  ├─ Missing http/https → Prompt user to add protocol\n  │  └─ Has protocol → Continue\n  └─ Add to valid URL list\n```\n\n> **Important Notes**:\n> - Prefetch only supports URL granularity, not directory or domain level\n> - To prefetch an entire directory, you need to provide a complete URL list of all files under that directory\n> - Wildcard purge is partially supported in cache purge scenarios (such as directory purge), but not supported in prefetch scenarios\n\n### C2: Execute Prefetch\n\n**Call** `CreatePrefetchTask`, passing parameters:\n- `ZoneId`: Site ID (from Scenario 0)\n- `Targets`: List of URLs to prefetch (passed format check)\n\n**Follow-up**: Inform user that the task has been submitted and provide JobId. If confirmation of execution result is needed, go to [Scenario D](#scenario-d-query-task-progress).\n\n### C3: Query Prefetch Origin Rate Limit (DescribePrefetchOriginLimit)\n\n> This interface is a whitelist beta feature, only use when user mentions \"prefetch rate limit\".\n\nCall `DescribePrefetchOriginLimit`.\n\n**Output suggestion**: If the domain has rate limit configuration, remind the user of the current bandwidth limit before prefetching; large-scale prefetch may be affected by this limit.\n\n## Scenario D: Query Task Progress\n\n**Trigger**: User says \"is purge done\", \"check task progress\", \"prefetch status\".\n\n### D1: Query Purge Tasks\n\nCall `DescribePurgeTasks`.\n\n### D2: Query Prefetch Tasks\n\nCall `DescribePrefetchTasks`, parameters and Filters similar to purge tasks.\n\n**Output suggestion**: Display task list in a table, marking tasks with `failed` and `timeout` status. If there are failed tasks, suggest users to check if URLs are correct or retry later.\n\n> Prefetch tasks additionally have `invalid` status, indicating origin response is non-2xx; need to check origin service.\n\n### D3: Auto-poll Progress After Submission\n\nAfter submitting purge / prefetch tasks, should actively poll task status until terminal state:\n\n1. Get `JobId` after submitting task\n2. Wait 5-10 seconds before querying status\n3. If still `processing`, continue waiting and retry (suggest 10-second interval)\n4. If reaching terminal state (`success` / `failed` / `timeout` / `canceled`), summarize results and display to user\n\n> Usually URL purge completes in 1-2 minutes, directory / Host purge in 3-5 minutes; prefetch time depends on resource size and quantity.\n\n## Scenario E: Batch URL Input\n\n**Trigger**: User provides a large number of URLs (read from file or directly paste multiple lines).\n\n### E1: Extract URLs from User's Pasted Text\n\nWhen user pastes multiple lines of URLs:\n1. Split text by lines, one URL per line\n2. Filter out empty lines and comment lines (starting with `#`)\n3. Ensure each URL starts with `http://` or `https://`\n4. Summarize valid URL count and display to user for confirmation\n\n### E2: Read URL List from File\n\nWhen user says \"import from file\", \"read URL list file\":\n1. Read user-specified file (support `.txt`, `.csv` and other plain text formats)\n2. Parse by lines, filter empty lines and comments\n3. Display parsed URL count and first few samples, ask user to confirm\n\n### E3: Batch Submission Considerations\n\n- **Check Quota**: First query DescribeContentQuota to ensure remaining quota ≥ URL count\n- **Single Batch Limit**: Number of URLs submitted each time is subject to single batch upper limit; automatically submit in batches when exceeding limit\n- **URL Deduplication**: Deduplicate before submission to avoid wasting quota\n- **Result Summary**: After all batches are submitted, summarize JobId list and failed items, query progress uniformly\n\nFile v1.1.0:references/acceleration/cert-manager.md\n\n# Certificate Automation Management\n\nManage EdgeOne domain HTTPS certificates: query certificate status, apply for free certificates, deploy custom certificates.\n\n## Scenario A: Query Certificate Status\n\n**Trigger**: User wants to view certificate list or check expiration time.\n\n### A1: Locate Target Site\n\nCall `DescribeZones`, using `zone-name` filter to match the site name specified by the user.\n\n> **Important**: Filter out sites with `Status` as `initializing` (these sites are still initializing and haven't completed creation).\n\nHandle based on results in three cases:\n\n**Case 1: Only 1 available site matched**\n\nDirectly use this site's `ZoneId`, proceed to A2.\n\n**Case 2: Multiple sites with same name matched**\n\nDisplay all **available** matching results to user, listing key information for distinction, **wait for user's explicit selection** before continuing:\n\n```\nFound multiple sites named \"xxx.com\", please confirm which one to query:\n\n  1. ZoneId: zone-aaa  Alias: prod   Access Mode: NS Access   Created: 2024-01-01\n  2. ZoneId: zone-bbb  Alias: test   Access Mode: CNAME Access  Created: 2025-06-01\n\nPlease reply with the number or ZoneId.\n```\n\n> After receiving user's response, use the selected `ZoneId` to proceed to A2.\n\n**Case 3: No available sites**\n\nPrompt user: \"No available site 'xxx.com' found, please check the site name or wait for site initialization to complete.\"\n\n### A2: Query Domain Certificate Information\n\nCall `DescribeAccelerationDomains`, read certificate information for each domain from the `AccelerationDomains[].Certificate` field in the response.\n\n> You can specify a domain to query via `Filters.domain-name`; not passing Filters returns all domains under the site.\n\nKey fields in each domain's `Certificate` structure:\n\n| Field | Meaning |\n|---|---|\n| `Certificate.Mode` | Certificate configuration mode: `disable` / `eofreecert` / `eofreecert_manual` / `sslcert` |\n| `Certificate.List[].CertId` | Certificate ID |\n| `Certificate.List[].Alias` | Certificate alias |\n| `Certificate.List[].Type` | Certificate type: `default` / `upload` / `managed` |\n| `Certificate.List[].ExpireTime` | Expiration time |\n| `Certificate.List[].Status` | Deployment status: `deployed` / `processing` / `applying` / `failed` / `issued` |\n| `Certificate.List[].SignAlgo` | Signature algorithm |\n\n**Output suggestion**: Display certificate information for each domain in table format, marking entries that are about to expire (≤30 days) or have abnormal status (`failed` / `applying`).\n\n## Scenario B: Apply and Deploy Free Certificate\n\n**Trigger**: User says \"apply for free certificate\", \"certificate is expiring soon\", \"renew certificate\".\n\n### B0: Locate Target Site\n\nIf user hasn't directly provided ZoneId, call `DescribeZones` using `zone-name` filter to match the site name specified by the user.\n\n> **Important**: Filter out sites with `Status` as `initializing` (these sites are still initializing and haven't completed creation).\n\n- **Only 1 available site matched**: Directly use this site's `ZoneId`, proceed to B1.\n- **Multiple sites with same name matched**: Display all **available** matching results to user, **wait for explicit selection** before continuing (display format same as Scenario A).\n- **No available sites**: Prompt user: \"No available site 'xxx.com' found, please check the site name or wait for site initialization to complete.\"\n\n### Access Mode Determination\n\nThe result of calling `DescribeZones` is also used to determine the access mode (`Type` field), taking different routes based on the result:\n\n| Access Mode | Free Certificate Application Method |\n|---|---|\n| NS Access / DNSPod Hosting | **Automatic Validation** — Directly call ModifyHostsCertificate |\n| CNAME Access | **Manual Validation** — Need to call ApplyFreeCertificate first, complete validation, then deploy |\n\n### B1: NS Access / DNSPod Hosting (Automatic Validation)\n\nCall `ModifyHostsCertificate`.\n\n> **Confirmation Prompt**: Deploying certificate will affect the domain's HTTPS service, need user confirmation before execution.\n\n### B2: CNAME Access (Manual Validation)\n\nRequires 4 steps:\n\n**Step 1**: Call `ApplyFreeCertificate` to initiate application.\n\n**Step 2**: Based on validation information in response, inform user to complete configuration.\n\n> After informing user, **wait for user to confirm configuration completion** before continuing to next step.\n\n**Step 3**: Call `CheckFreeCertificateVerification` to check validation result\n\n- Success: Response contains certificate information, indicating certificate has been issued\n- Failure: Need to check if validation configuration is correct\n\n**Step 4**: Call `ModifyHostsCertificate` to deploy free certificate.\n\n> **Confirmation Prompt**: Deploying certificate will affect the domain's HTTPS service, need user confirmation before execution.\n\n## Scenario C: Deploy Custom Certificate\n\n**Trigger**: User says \"configure custom certificate\", \"uploaded certificate\", or provides CertId.\n\n### C0: Locate Target Site\n\nIf user hasn't directly provided ZoneId, call `DescribeZones` using `zone-name` filter to match the site name specified by the user.\n\n> **Important**: Filter out sites with `Status` as `initializing` (these sites are still initializing and haven't completed creation).\n\n- **Only 1 available site matched**: Directly use this site's `ZoneId`, proceed to next step.\n- **Multiple sites with same name matched**: Display all **available** matching results to user, **wait for explicit selection** before continuing (display format same as Scenario A).\n- **No available sites**: Prompt user: \"No available site 'xxx.com' found, please check the site name or wait for site initialization to complete.\"\n\n### C1: Query SSL Certificates Applicable to Target Domain\n\nIf user hasn't provided CertId, or wants to select from existing certificates, call `ssl:DescribeCertificates` to query certificate list, then filter out certificates applicable to the target domain.\n\n**Call Parameter Suggestions**:\n- `SearchKey`: Pass in target domain (e.g., `a-1.qcdntest.com`), can fuzzy match domain field to narrow return range\n- `CertificateType`: Pass `SVR`, only query server certificates (exclude client CA certificates)\n- `Limit`: Suggest passing `1000` to ensure no omissions\n\n**Filter Rules**: For each returned certificate, check if any entry in the `SubjectAltName` list matches the target domain:\n\n| Match Type | Description | Example |\n|---|---|---|\n| Exact Match | `SubjectAltName` has an entry exactly the same as target domain | `a-1.qcdntest.com` |\n| Wildcard Match | `SubjectAltName` has a `*.xxx` entry, and target domain is its direct subdomain (only one level) | `*.qcdntest.com` matches `a-1.qcdntest.com` |\n\n**Availability Determination**: After filtering matching certificates, mark availability status for each certificate based on the following fields:\n\n| Field | Meaning | Availability Condition |\n|---|---|---|\n| `Status` | Certificate status | Must be `1` (Approved) |\n| `CertEndTime` | Expiration time | Days until today > 0 (Not expired) |\n| `Deployable` | Whether deployable | Must be `true` |\n\n**Output suggestion**: Display all matching certificates in a table, marking availability:\n\n```\nCertificates applicable to a-1.qcdntest.com:\n\nCert ID      Alias          Expiration           Days Left  Status     Deployable  Availability\n------------ -------------- -------------------- ---------- ---------- ----------- ------------\nzVq87w0D     my-cert        2032-09-23 05:10:56  2371 days  Approved   ✅          ✅ Available\nQxbtGBIM     old-cert       2025-01-01 00:00:00  -86 days   Expired    ❌          ❌ Expired\n```\n\nIf no matching certificate is found, inform user that they need to first go to [SSL Certificate Console](https://console.cloud.tencent.com/ssl) to upload or apply for a certificate covering this domain.\n\n### C2: Deploy Certificate\n\nAfter user selects certificate from C1 results, call `ModifyHostsCertificate` (`Mode=sslcert`, `ServerCertInfo[{CertId}]`).\n\n> **No Automatic Deployment**: **Must** confirm deployment domain and certificate ID with user before execution.\n\n## Scenario D: Batch Certificate Inspection\n\n**Trigger**: User says \"check certificates for all domains\", \"which certificates are expiring soon\".\n\n### Process\n\n1. Call `DescribeZones` to get all sites\n   - **Important**: Filter out sites with `Status` as `initializing` (these sites are still initializing and haven't completed creation)\n   - **Critical**: **Must use pagination** to retrieve all sites:\n     - Set `Limit=100` (maximum value)\n     - Set `Offset=0` initially, increment by 100 each iteration\n     - Loop until `Offset + Limit >= TotalCount`\n     - Merge all paginated results\n   - Refer to [zone-discovery.md](../api/zone-discovery.md) for detailed pagination implementation\n2. Call `DescribeAccelerationDomains` for each **available** site, read certificate information from each `AccelerationDomains[].Certificate` field in the response\n3. Summarize output, marking the following anomalies:\n   - Certificates with `Certificate.List[].Status` as `failed` or `applying`\n   - Certificates with `Certificate.List[].ExpireTime` ≤30 days from today\n   - Domains with `Certificate.Mode` as `disable` or `Certificate` is null (no certificate configured)\n\n### Output Format Suggestion\n\n```markdown\n## Certificate Inspection Report\n\n| Site | Domain | Cert ID | Expiration | Days Left | Status |\n|---|---|---|---|---|---|\n| example.com | *.example.com | teo-xxx | 2026-04-15 | 29 days | Expiring Soon |\n| example.com | api.example.com | teo-yyy | 2026-09-01 | 168 days | Normal |\n```\n\nFile v1.1.0:references/acceleration/zone-onboarding.md\n\n# Site One-Click Onboarding Guide\n\nEnd-to-end domain onboarding to EdgeOne: confirm plan → create site → verify ownership → add acceleration domain → apply and deploy certificate.\n\n## Important Concepts\n\n### Alias Zone Name (AliasZoneName)\n\nWhen you create two or more sites with the same site name, you need to use an **Alias Zone Name** to distinguish them.\n\n**Use Cases**:\n- Same domain using different access modes (CNAME access, DNSPod hosting access)\n- Same domain configured with different acceleration or security strategies\n\n**Format Requirements**:\n- Allows combination of numbers, English letters, `.`, `-`, and `_`\n- Length limit: within 200 characters\n- Examples: `site-prod`, `site-test`, `site_backup`\n\n**Access Mode Restrictions**:\n- ✅ **CNAME Access**: Supports creating multiple sites with same name\n- ✅ **DNSPod Hosting Access**: Supports creating multiple sites with same name\n- ❌ **NS Access**: A domain can only be accessed via NS once, does not support sites with same name\n- ⚠️ **Mutual Exclusion Rule**: Domains accessed via NS cannot use other access modes; domains accessed via CNAME/DNSPod hosting cannot use NS access\n\n### Site Status Determination Logic\n\nWhen displaying site status to users, the effective status should be determined by evaluating the following fields from `DescribeZones` response **in order** (first match wins):\n\n| Priority | Condition | Display Status |\n|---|---|---|\n| 1 | `Status == \"initializing\"` | Initializing — **must be filtered out, do not display to user** |\n| 2 | `Status == \"forbidden\"` | forbidden |\n| 3 | `Status == \"deleted\"` | Deleted |\n| 4 | `ActiveStatus == \"changing\"` | Changing |\n| 5 | `ActiveStatus == \"inPausing\"` | Pausing |\n| 6 | `Paused == true` | Paused |\n| 7 | None of the above | Active |\n\n> **Important**: This logic must be applied in all scenarios where site status is displayed, including site selection (D0) and status queries (F).\n\n## Access Mode Description\n\nEdgeOne supports four site access modes:\n\n### Access Modes with Domain\n\n1. **DNSPod Hosting Access** (dnspodAccess)\n   - **Prerequisites**: Domain is hosted in DNSPod and status is normal\n   - **Advantages**: EdgeOne can directly and automatically complete ownership verification and configuration, best experience\n   - **Recommendation**: Strongly recommended if conditions are met\n   - **Available Features**: Layer 7 acceleration, Layer 4 proxy, security protection, edge functions\n\n2. **NS Access** (full)\n   - **Requirements**: Need to switch NS records to EdgeOne-provided Name Servers at domain registrar\n   - **Characteristics**: EdgeOne fully takes over domain DNS resolution\n   - **Available Features**: Layer 7 acceleration, Layer 4 proxy, security protection, edge functions, DNS resolution\n\n3. **CNAME Access** (partial)\n   - **Requirements**: Need to manually add TXT record to verify ownership\n   - **Characteristics**: Only need to configure CNAME record pointing to EdgeOne, NS record unchanged\n   - **Available Features**: Layer 7 acceleration, Layer 4 proxy, security protection, edge functions\n\n### Access Mode without Domain\n\n4. **No Domain Access** (noDomainAccess)\n   - **Applicable Scenarios**: Temporarily no domain, or only need Layer 4 proxy and edge functions\n   - **Characteristics**:\n     - Can create site without providing domain\n     - No ownership verification needed\n     - Can directly use Layer 4 proxy and edge functions after creation\n   - **Available Features**: Only supports Layer 4 proxy, edge functions\n   - **Future Extension**: After site creation, can add Layer 7 acceleration domains anytime\n\n## End-to-End Process Overview\n\n### Access Process with Domain\n\n```\n1. Confirm Plan (DescribePlans / DescribeAvailablePlans / CreatePlan)\n       ↓\n2. Create Site (CreateZone)\n   ├─ B0: Determine if domain meets specifications\n   │  ├─ Meets → Continue with domain access process\n   │  └─ Doesn't meet → Prompt to use no-domain access\n   ├─ B1: Detect DNSPod hosting status (DescribeDomain)\n   │  ├─ Meets conditions: Prioritize recommending DNSPod hosting access\n   │  └─ Doesn't meet: Provide CNAME access and NS access\n   ├─ B1.5: Domain conflict pre-check (CreateZone DryRun)\n   │  ├─ No conflict → Continue creation\n   │  ├─ CNAME/DNSPod conflict → Require AliasZoneName\n   │  └─ NS conflict → Terminate creation (NS access is exclusive)\n   ├─ B2: Confirm access mode and parameters\n   │  ├─ Select access mode (DNSPod hosting / NS / CNAME)\n   │  ├─ Select acceleration area (mainland/global requires ICP filing)\n   │  └─ If conflict exists, provide Alias Zone Name\n   ├─ DNSPod hosting access: Automatically complete validation, jump directly to step 4\n   ├─ NS access: Switch DNS server\n   └─ CNAME access: Add TXT record or file validation\n       ↓\n3. Verify Ownership (VerifyOwnership) — Can be skipped, verify later\n       ↓\n4. Add Acceleration Domain (CreateAccelerationDomain)\n       ↓\n5. Apply and Deploy HTTPS Certificate (see cert-manager.md)\n       ↓\n   Onboarding Complete\n```\n\n### No Domain Access Process\n\n```\n1. Confirm Plan (DescribePlans / DescribeAvailablePlans / CreatePlan)\n       ↓\n2. Create Site (CreateZone, Type = noDomainAccess)\n   - Keep ZoneName empty\n   - Keep Area empty\n   - No ownership verification needed\n       ↓\n3. Configure Layer 4 proxy or edge functions\n       ↓\n   Onboarding Complete\n```\n\n> Can check verification status anytime via DescribeIdentifications.\n> For certificate-related queries and operations, refer to [cert-manager.md](cert-manager.md).\n\n## Scenario A: Confirm Plan\n\n**Trigger**: First step of the process, must confirm plan before creating site.\n\n### A1: Query Existing Plans (DescribePlans)\n\nCall `DescribePlans` to query plans under the account.\n\n#### Filter Logic\n\nFrom returned plan list, filter available plans by the following conditions:\n\n1. **Bindable**: `Bindable == \"true\"`\n2. **Normal Status**: `Status == \"normal\"`\n3. **Sufficient Quota**: Bound sites < Site quota limit\n\n> Only plans meeting all 3 conditions above can be used for binding.\n\n#### Has Available Plans\n\n> **No Automatic Binding**: Binding plan will consume site quota. **Must** first display plan information to user and wait for explicit selection before binding; never decide on your own.\n\n**Must display all available plans** for user selection, no omissions or truncation:\n\n- If **Only 1 plan**: Still need user confirmation before use\n- If **Multiple plans**:\n  - **Display Info**: Plan ID, plan type, bound site count\n  - **Display Method**: If plan count exceeds structured interaction tool's option limit, display in batches or provide input method to ensure user can see and select all plans\n  - **Suggested Sorting**: Sort by bound site count from least to most, convenient for user to select plans with sufficient quota\n- User can also choose **not to bind existing plan**, go to A2 to purchase new plan\n\n#### No Available Plans\n\nGo to A2.\n\n### A2: Purchase New Plan (DescribeAvailablePlans → CreatePlan)\n\nCall `DescribeAvailablePlans` to query plan types available for purchase under current account, display options to user.\n\n> **No Automatic Purchase**: Purchasing plan will incur actual charges. **Must** display plan type and pricing info to user, and wait for explicit confirmation before calling `CreatePlan`. Never skip confirmation or decide on your own.\n\nAfter user explicit confirmation, call `CreatePlan` to purchase plan.\n\nIf user confirms not to purchase, remind: **Site needs to be bound to plan to provide normal service**. Sites not bound to plan will be in `init` status and unable to take effect.\n\n### Next Step\n\nAfter plan confirmation, carry PlanId to [Scenario B: Create Site](#scenario-b-create-site).\n\n## Scenario B: Create Site\n\n**Trigger**: User says \"onboard example.com to EdgeOne\", \"create site\", \"create new site\", or subsequent step after plan confirmation.\n\n> If user directly triggers this scenario (without going through Scenario A), must first guide through [Scenario A: Confirm Plan](#scenario-a-confirm-plan) before continuing.\n\n> **No Automatic Creation**: Creating site will consume plan's site quota. **Must** confirm site domain, access mode, and acceleration area with user before execution; never decide on your own.\n\n### B0: Determine Access Mode Type\n\n**First determine if the site name provided by user meets domain specifications**:\n\n1. **Meets domain specifications** (e.g., `example.com`, `test.com.cn`):\n   - Enter access process with domain → Go to [B1: Detect DNSPod Hosting Status](#b1-detect-dnspod-hosting-status)\n\n2. **Doesn't meet domain specifications or user explicitly indicates no domain**:\n   - Prompt user: \"The site name you provided doesn't meet domain specifications. EdgeOne supports no-domain access mode, which is limited to Layer 4 proxy and edge functions, and Layer 7 acceleration domains can be added later. Do you want to use no-domain access mode?\"\n   - If user confirms → Go to [B3: No Domain Access](#b3-no-domain-access)\n   - If user declines → Prompt user to provide valid second-level domain\n\n> **Domain Specifications**: Valid second-level domain (e.g., example.com), does not accept third-level and above domains (e.g., www.example.com) as site name.\n\n### B1: Detect DNSPod Hosting Status\n\nBefore displaying access mode options to user, first try to detect if domain is hosted in DNSPod to prioritize recommending DNSPod hosting access mode.\n\n**Steps:**\n\n1. **Call DNSPod's DescribeDomain interface**, pass in the domain to onboard\n   \n2. **Determine if DNSPod hosting access conditions are met**:\n   - Domain exists in DNSPod\n   - `Status` field is `ENABLE` or `LOCK`\n   - `DnsStatus` field is empty string (normal status)\n\n3. **Exception Handling**:\n   - If interface call fails (e.g., no permission, service unavailable), handle silently, don't display DNSPod hosting access option\n   - If domain doesn't exist or status doesn't meet conditions, don't display DNSPod hosting access option\n\n> **Note**: The `DescribeDomain` interface only returns errors for no permission or domain not found, won't return service authorization related error codes.\n\n### B1.5: Domain Conflict Pre-check\n\nBefore formally creating site, perform pre-check to determine if domain has been accessed to avoid creation failure due to domain conflict.\n\n**Steps:**\n\n1. **Call CreateZone interface for pre-check**\n   - Pass parameter `DryRun: true`\n   - Pass domain to onboard `ZoneName`\n   - Pass user-selected access mode `Type`\n\n2. **Determine pre-check result**:\n\n   **a) Pre-check succeeds** (no error returned)\n   - Indicates domain hasn't been accessed, can directly create\n   - Go to [B2: Confirm Access Mode and Parameters](#b2-confirm-access-mode-and-parameters)\n\n   **b) Returns `ResourceInUse.Zone` error**\n   - Indicates domain has been accessed via CNAME or DNSPod hosting\n   - Prompt user: \"This domain has been accessed, need to set Alias Zone Name to distinguish different sites\"\n   - Guide user to provide `AliasZoneName` (Alias Zone Name)\n   - Go to [B2: Confirm Access Mode and Parameters](#b2-confirm-access-mode-and-parameters)\n\n   **c) Returns `ResourceInUse.Others` or `ResourceInUse.OthersNS` error**\n   - Indicates domain has been accessed via **NS access**\n   - Prompt user: \"This domain has been accessed via NS access. NS access sites can only be accessed once and cannot use other access modes. If you want to use other access modes, please delete the existing NS access site first.\"\n   - **Terminate creation process**\n\n> **Important Notes**:\n> - NS access has exclusivity; a domain can only be accessed via NS once\n> - Domains accessed via NS cannot use CNAME or DNSPod hosting access\n> - Domains accessed via CNAME or DNSPod hosting cannot use NS access (but can continue using CNAME or DNSPod hosting to create sites with same name)\n\n### B2: Confirm Access Mode and Parameters\n\n**Call** `CreateZone`. User needs to provide:\n- **Site Domain**: Root domain to onboard\n- **Access Mode**: Display available options based on B1 detection results\n  - If DNSPod hosting conditions are met: **Prioritize recommending** DNSPod hosting access (dnspod), also provide CNAME access (partial) and NS access (full) options\n  - If conditions not met: Only provide CNAME access (partial) and NS access (full) options\n- **Acceleration Area** (Area): Optional values are mainland (Mainland China), overseas (Global excluding Mainland China), global (Global)\n  - **mainland (Mainland China)**: ⚠️ **Requires domain to have completed ICP filing with MIIT**\n  - **global (Global)**: ⚠️ **Requires domain to have completed ICP filing with MIIT**\n  - **overseas (Global excluding Mainland China)**: No filing requirement\n- **Alias Zone Name** (AliasZoneName): **Only needed when B1.5 pre-check returns domain conflict**\n  - Provided by user to distinguish sites with same name\n  - Format requirements: combination of numbers, English letters, `.`, `-`, `_`, within 200 characters\n\n> **Important Notes**:\n> - When selecting `mainland` or `global` area, must remind user to confirm domain has completed ICP filing, otherwise site will not be able to onboard and use normally.\n> - If B1.5 pre-check finds domain conflict, must require user to provide `AliasZoneName` parameter.\n\nSuggest passing PlanId directly when creating.\n\n> When not passing PlanId, site is in `init` status, need to bind later via BindZoneToPlan.\n>\n> **No Automatic Binding**: Whether passing PlanId via `CreateZone` or later calling `BindZoneToPlan`, **must** obtain user's explicit confirmation beforehand; never decide on your own which plan to bind.\n\n#### Exception Handling: Service Authorization Missing\n\n**Only when user selects DNSPod hosting access mode**, calling `CreateZone` may return error code `OperationDenied.DNSPodUnauthorizedRoleOperation`, indicating service authorization is missing.\n\n**Handling Steps**:\n\n1. **Automatically create service authorization**: Call CAM's `CreateServiceLinkedRole` interface\n   - `QCSServiceName`: `[\"DnspodaccesEO.TEO.cloud.tencent.com\"]`\n   - `Description`: `\"This role is a service-linked role for Tencent EdgeOne Platform (TEO). This role will query your domain status and related DNS records in DNSPod within the permission scope of associated policies, and help you quickly complete DNS modification to switch acceleration service to EO in one-click DNS modification scenarios\"`\n\n2. **Retry site creation**:\n   - If service authorization creation succeeds, retry calling `CreateZone` to create site\n   - If service authorization creation fails, enable fallback mode: prompt user to use NS access or CNAME access\n\n### Next Step for DNSPod Hosting Access\n\n> In DNSPod hosting access mode, EdgeOne will automatically complete ownership verification.\n\nAfter site creation succeeds:\n- Site will automatically complete ownership verification\n- Can directly go to [Scenario D: Add Acceleration Domain](#scenario-d-add-acceleration-domain)\n\n### Next Step for NS Access\n\nInform user that they need to modify DNS server to NameServers returned in response at domain registrar, then go to [Scenario C: Verify Ownership](#scenario-c-verify-ownership).\n\n### Next Step for CNAME Access\n\nInform user of two validation methods (choose one), get validation info from response:\n\n1. **DNS Validation**: Add TXT record in DNS\n2. **File Validation**: Place validation file in origin root directory\n\nAfter user confirms configuration complete, go to [Scenario C: Verify Ownership](#scenario-c-verify-ownership).\n\n### B3: No Domain Access\n\n**Applicable Scenarios**: User temporarily has no domain or only needs Layer 4 proxy and edge functions.\n\n**Call** `CreateZone`, parameters as follows:\n- `Type`: `noDomainAccess`\n- `ZoneName`: **Keep as empty string**\n- `Area`: **Keep as empty string**\n- `PlanId`: Pass confirmed plan ID\n\n> **Important Note**: In no-domain access mode, ZoneName and Area parameters must be kept empty, otherwise interface call will fail.\n\n**After creation succeeds**:\n- Site needs no ownership verification\n- Can directly use Layer 4 proxy and edge functions\n- Inform user: \"Site created successfully, you can now configure Layer 4 proxy or edge functions. If you need Layer 7 acceleration features, you can add acceleration domains anytime.\"\n\n**Follow-up Operations**:\n- Configure Layer 4 proxy: Refer to Layer 4 proxy related documentation\n- Configure edge functions: Refer to edge functions related documentation\n\n## Scenario C: Verify Ownership\n\n**Trigger**: User says \"verify site\", \"check DNS switch\", \"ownership verification\", or subsequent step after site creation.\n\n> User can choose to skip ownership verification and directly go to [Scenario D: Add Acceleration Domain](#scenario-d-add-acceleration-domain), verify later.\n\n### C1: Query Verification Status (DescribeIdentifications)\n\nBefore triggering verification, first call `DescribeIdentifications` to query current verification status.\n\n**Decision**:\n- If `Status` is `finished`, no need to verify again, go directly to next step\n- If `Status` is `pending`, inform user to configure DNS TXT record or file validation based on validation info in response\n\n### C2: Trigger Verification (VerifyOwnership)\n\nAfter user confirms DNS / file configuration complete, call `VerifyOwnership`.\n\n**NS Access Scenario**: Verify if DNS server switch succeeded. DNS switch usually takes 24-48 hours to take effect globally; if verification fails, suggest user retry later.\n\n**CNAME Access Scenario**: Verify if TXT record or file is configured correctly. If site passes ownership verification, adding domains later won't need verification again.\n\n## Scenario D: Add Acceleration Domain\n\n**Trigger**: User says \"add domain\", \"configure acceleration domain\", \"onboard subdomain\", or subsequent step after ownership verification completion (or skip).\n\n> **No-Domain Access Sites**: Sites created via no-domain access mode can also add Layer 7 acceleration domains anytime; after adding, can use complete Layer 7 acceleration features.\n\n### D0: Determine Target Site\n\n> If entering this scenario from a continuous flow of Scenario B/C, ZoneId is already known; you can skip this step and go directly to D1.\n\nWhen user directly triggers \"add domain\", you need to first determine which site to add the domain to.\n\n**Steps:**\n\n1. **Extract root domain**: Extract the root domain (e.g., `example.com`) from the acceleration domain provided by user (e.g., `www.example.com`).\n\n2. **Query matching sites**: Call `DescribeZones` with `zone-name` filter by root domain:\n   ```\n   --Filters '[{\"Name\":\"zone-name\",\"Values\":[\"example.com\"]}]'\n   ```\n\n3. **Filter and handle based on query results**:\n\n   First, filter out sites with `Status == \"initializing\"` — these sites are still initializing and must not be displayed.\n\n   Then handle the remaining sites:\n\n   - **No matching site** (or all filtered out): Prompt user that the root domain has not been onboarded to EdgeOne, guide to [Scenario A: Confirm Plan](#scenario-a-confirm-plan) to begin full onboarding process.\n\n   - **Only 1 site**: Display site info (ZoneId, alias, access mode, acceleration area, status) to user, proceed to D1 after confirmation.\n\n   - **Multiple sites** (same root domain may have multiple sites): **Must** display all matching sites for user selection; never automatically select the first one or any arbitrary one. Display info should include:\n     - **Site Alias** (AliasZoneName) — the most intuitive distinguishing identifier\n     - **ZoneId**\n     - **Access Mode** (Type: dnsPodAccess / partial / full)\n     - **Acceleration Area** (Area: mainland / overseas / global)\n     - **Status**: Determined using the [Site Status Determination Logic](#site-status-determination-logic)\n     - Suggest prioritizing sites with `Active` status\n\n   > **No Automatic Selection**: When multiple matching sites exist, **must** wait for user's explicit selection before continuing; never decide on your own.\n\n### D1: Collect Parameters\n\nNeed to confirm following information with user before calling:\n\n1. **Acceleration Domain** (DomainName): Subdomain to onboard, e.g., `www.example.com`\n2. **IPv6 Access** (IPv6Status): Whether to enable IPv6 access, values:\n   - `follow`: Follow site IPv6 configuration (default)\n   - `on`: Enable\n   - `off`: Disable\n3. **Origin Configuration** (OriginInfo): See [OriginInfo Data Structure](#origininfo-data-structure) below\n4. **Origin Protocol** (OriginProtocol, optional): FOLLOW (default) / HTTP / HTTPS\n5. **Origin Port** (optional): HTTP origin port (default 80) / HTTPS origin port (default 443)\n\n#### OriginInfo Data Structure\n\nOriginInfo is a required parameter for `CreateAccelerationDomain`, defining origin information.\n\n##### Required Fields\n\n| Field | Type | Description |\n|---|---|---|\n| **OriginType** | string | Origin type, see values below |\n| **Origin** | string | Origin address, fill in different values based on OriginType |\n\n##### OriginType Values and Origin Mapping\n\n| OriginType | Description | Origin Value |\n|---|---|---|\n| `IP_DOMAIN` | IPv4, IPv6, or domain type origin | IP address or domain, e.g., `1.1.1.1`, `origin.example.com` |\n| `COS` | Tencent Cloud COS object storage origin | COS bucket access domain |\n| `AWS_S3` | AWS S3 object storage origin | S3 bucket access domain |\n| `ORIGIN_GROUP` | Origin group type origin | Origin group ID; if referencing another site's origin group, format: `{OriginGroupID}@{ZoneID}` |\n| `VOD` | Cloud VOD | Cloud VOD application ID |\n| `LB` | Load balancer (whitelist only) | Load balancer instance ID; if referencing another site's LB, format: `{LBID}@{ZoneID}` |\n| `SPACE` | Origin offload (whitelist only) | Origin offload space ID |\n\n##### Optional Fields\n\n| Field | Type | Applicable Scenario | Description |\n|---|---|---|---|\n| **HostHeader** | string | Only when `OriginType = IP_DOMAIN` | Custom origin HOST header. **Do not pass this field** for other origin types, otherwise it will cause errors |\n| **PrivateAccess** | string | Only when `OriginType = COS` or `AWS_S3` | Whether to use private authentication: `on` / `off` (default off) |\n| **PrivateParameters** | list | Only when `PrivateAccess = on` | Private authentication parameter list |\n| **BackupOrigin** | string | Only when `OriginType = ORIGIN_GROUP` | Backup origin group ID (legacy feature, not recommended) |\n| **VodOriginScope** | string | Only when `OriginType = VOD` | Origin scope: `all` (default, all files in app) / `bucket` (specified bucket) |\n| **VodBucketId** | string | Only when `OriginType = VOD` and `VodOriginScope = bucket` | VOD bucket ID |\n\n##### Most Common Scenario Examples\n\n**IP/Domain origin** (most common):\n```json\n{\n  \"OriginType\": \"IP_DOMAIN\",\n  \"Origin\": \"1.1.1.1\"\n}\n```\n\n**COS origin (private access)**:\n```json\n{\n  \"OriginType\": \"COS\",\n  \"Origin\": \"bucket-xxx.cos.ap-guangzhou.myqcloud.com\",\n  \"PrivateAccess\": \"on\",\n  \"PrivateParameters\": [{\"Name\": \"SecretId\", \"Value\": \"xxx\"}, {\"Name\": \"SecretKey\", \"Value\": \"xxx\"}]\n}\n```\n\n**Origin group**:\n```json\n{\n  \"OriginType\": \"ORIGIN_GROUP\",\n  \"Origin\": \"og-testorigin\"\n}\n```\n\n### D2: Call CreateAccelerationDomain\n\n> **No Automatic Addition**: Adding acceleration domain will change online DNS configuration. **Must** complete parameter collection in D1 and obtain user's explicit confirmation before execution; never decide on your own.\n\nCall `CreateAccelerationDomain` after user confirmation.\n\n**Next Step**: Inform user that they need to add CNAME record in DNS, pointing domain to EdgeOne-assigned CNAME address (can query `Cname` field via `DescribeAccelerationDomains`).\n\n## Scenario E: Apply and Deploy HTTPS Certificate\n\n**Trigger**: After domain addition complete, user says \"configure HTTPS\", \"apply for certificate\", or as final step of onboarding process.\n\n> Complete certificate management (CNAME manual validation, deploy custom certificate, batch inspection, etc.) refer to [cert-manager.md](cert-manager.md).\n\n### E1: NS Access / DNSPod Hosting Access (Automatic Validation, One-Step Complete)\n\n> **Applicable Scenarios**: In NS access mode or DNSPod hosting access mode, EdgeOne can directly control DNS records, so can automatically complete certificate application and deployment.\n\n> **No Automatic Deployment**: Deploying certificate will directly affect domain's HTTPS service. **Must** inform user which domains will deploy which certificates, and wait for explicit confirmation before calling `ModifyHostsCertificate`.\n\n### E2: CNAME Access (Manual Validation)\n\nCNAME access needs to first apply for certificate, complete domain validation, then deploy; process is longer. Please refer to [cert-manager.md Scenario B2](cert-manager.md#b2-cname-access-manual-validation) for complete steps.\n\n## Scenario F: View Onboarding Status\n\n**Trigger**: User says \"check site status\", \"is domain onboarded\".\n\nCall `DescribeZones` to query target site status.\n\n> **Important**: When displaying site status, must use the [Site Status Determination Logic](#site-status-determination-logic) to determine and display the effective status. Sites with `Status == \"initializing\"` must be filtered out and not displayed to users.\n\n> Refer to [../api/zone-discovery.md](../api/zone-discovery.md) for more query methods.\n\nFile v1.1.0:references/api/api-discovery.md\n\n# EdgeOne API Discovery\n\nThe tccli service name for EdgeOne is **teo**.\nTypically, reference files already specify the API name to call — just look up the API documentation directly;\nuse fallback discovery only when references do not cover the scenario.\n\n---\n\n## Main Flow: Known API Name\n\n### 1. Read the API Documentation\n\nGet parameter descriptions and request examples for a specific API:\n\n```sh\ncurl -s https://cloudcache.tencentcs.com/capi/refs/service/teo/action/CreatePurgeTask.md\n```\n\n### 2. Read Data Structures\n\nComplex data structures referenced in the API documentation can be further examined:\n\n```sh\ncurl -s https://cloudcache.tencentcs.com/capi/refs/service/teo/model/Task.md\n```\n\n---\n\n## Fallback: Not Sure Which API to Call\n\nWhen references do not specify an API, or you need to explore uncovered scenarios, search in the following order:\n\n### 1. Search the API List\n\nSearch for keywords in the API list (the Action name is the second argument after `tccli teo`):\n\n```sh\ncurl -s https://cloudcache.tencentcs.com/capi/refs/service/teo/actions.md \\\n  | grep -i \"purge\\|cache\"\n```\n\n### 2. Search Best Practices\n\nCheck if there are best practices matching the current scenario (with complete call examples):\n\n```sh\ncurl -s https://cloudcache.tencentcs.com/capi/refs/service/teo/practices.md \\\n  | grep -i \"purge\\|refresh\"\n```\n\n### 3. Read Best Practice Details\n\n```sh\ncurl -s https://cloudcache.tencentcs.com/capi/refs/service/teo/practice/practice-53.md\n```\n\n---\n\nFile v1.1.0:references/api/auth.md\n\n# Configure TCCLI Credentials\n\n## Login Method\n\nFirst, run the following command to verify the current login status:\n\n```sh\ntccli cvm DescribeRegions --request-client \"tencent-edgeone-skill/1.1.0 module/api\" 2>&1; echo \"EXIT_CODE:$?\"\n```\n\n- If a normal result is returned, you are already logged in — no need to log in again.\n- If it shows `secretId is invalid` or other authentication errors, you are not logged in and need to continue with the login command below.\n\nBrowser-based authorization login is recommended — no need to manually enter SecretId/SecretKey, credentials are automatically saved locally:\n\n```sh\ntccli auth login\n```\n\nAfter execution, TCCLI will start a temporary port on your machine and print an OAuth authorization link (it usually also opens automatically in the default browser). Once the user completes login and authorization in the browser, TCCLI receives the callback, writes the credentials, and exits.\n\n- If the browser does not open automatically, copy the link printed in the terminal and open it manually in a browser.\n- Upon success, it will display: \"Login successful, credentials have been written to: ...\"\n\n---\n\n## Agent Operating Guidelines\n\n**Determining whether login is needed:**\n\n1. First run `tccli cvm DescribeRegions`.\n2. If a **reasonable success result** is returned, consider the user logged in and proceed with subsequent operations.\n3. If an error is returned or the command cannot execute, you must first run `tccli auth login`.\n4. Never ask the user for `SecretId` / `SecretKey`, and do not execute commands that might expose credential contents (especially `tccli configure list`).\n\n\n> ⚠️ The Agent must not assume TCCLI is usable based solely on the user's verbal statement or potentially stale credential files on the machine.\n\n**When running `tccli auth login`:**\n\n- This command will **block** until the user completes browser login (or it times out).\n- The Agent should clearly inform the user: \"Please open the authorization link shown in the terminal/tool output and complete login in the browser; the command will end automatically once done.\"\n\n---\n\n## Multi-Account & Logout\n\n| Operation | Command |\n|------|------|\n| Login default account | `tccli auth login` |\n| Login specific account | `tccli auth login --profile user1` |\n| Logout default account | `tccli auth logout` |\n| Logout specific account | `tccli auth logout --profile user1` |\n\nCredential file notes:\n- Default account credentials are saved in `default.credential`\n- Specific account credentials are saved in `<profile-name>.credential` (e.g., `user1.credential`)\n\n## Security Reminder\n\n> Using `tccli configure` to manually enter SecretId / SecretKey is **not recommended**. Manually configured keys are stored in plaintext locally and risk being leaked. Always use the `tccli auth login` browser authorization method.\n\nFile v1.1.0:references/api/dnspod-integration.md\n\n# DNSPod Integration API Reference\n\nEdgeOne supports DNSPod hosting access mode, enabling one-click domain onboarding and automated configuration. This document explains how to call related APIs.\n\n## Query Domain Hosting Status\n\n### DescribeDomain (DNSPod)\n\n**Purpose**: Query whether domain is hosted in DNSPod and if hosting status meets EdgeOne access conditions.\n\n**Invocation Example**:\n\n```bash\ntccli dnspod DescribeDomain --Domain \"example.com\" --reque\n\nArchive v1.0.2: 23 files, 68314 bytes\n\nFiles: references/acceleration/cache-purge.md (12388b), references/acceleration/cert-manager.md (9616b), references/acceleration/README.md (843b), references/acceleration/zone-onboarding.md (25281b), references/api/api-discovery.md (1480b), references/api/auth.md (2857b), references/api/dnspod-integration.md (6977b), references/api/install.md (1921b), references/api/README.md (4764b), references/api/zone-discovery.md (3477b), references/observability/eo-log-analyzer.md (14009b), references/observability/eo-log-downloader.md (6385b), references/observability/eo-origin-health-check.md (18870b), references/observability/eo-traffic-daily-report.md (24475b), references/observability/README.md (2766b), references/security/domain-blacklist-inspector.md (5013b), references/security/ip-threat-blacklist.md (8529b), references/security/README.md (2654b), references/security/security-template-audit.md (4637b), references/security/security-weekly-report.md (4979b), skill-card.md (2971b), SKILL.md (3874b), _meta.json (140b)\n\nArchive v1.0.1: 23 files, 67362 bytes\n\nFiles: references/acceleration/cache-purge.md (12388b), references/acceleration/cert-manager.md (9616b), references/acceleration/README.md (653b), references/acceleration/zone-onboarding.md (25281b), references/api/api-discovery.md (1480b), references/api/auth.md (2773b), references/api/dnspod-integration.md (6857b), references/api/install.md (1690b), references/api/README.md (3511b), references/api/zone-discovery.md (3477b), references/observability/eo-log-analyzer.md (14009b), references/observability/eo-log-downloader.md (6385b), references/observability/eo-origin-health-check.md (18870b), references/observability/eo-traffic-daily-report.md (24475b), references/observability/README.md (2557b), references/security/domain-blacklist-inspector.md (5013b), references/security/ip-threat-blacklist.md (8529b), references/security/README.md (2453b), references/security/security-template-audit.md (4637b), references/security/security-weekly-report.md (4979b), skill-card.md (3120b), SKILL.md (3874b), _meta.json (140b)\n\nArchive v1.0.0: 22 files, 66083 bytes\n\nFiles: references/acceleration/cache-purge.md (12388b), references/acceleration/cert-manager.md (9616b), references/acceleration/README.md (707b), references/acceleration/zone-onboarding.md (25281b), references/api/api-discovery.md (1480b), references/api/auth.md (2773b), references/api/dnspod-integration.md (6857b), references/api/install.md (1719b), references/api/README.md (3741b), references/api/zone-discovery.md (3477b), references/observability/eo-log-analyzer.md (14223b), references/observability/eo-log-downloader.md (6469b), references/observability/eo-origin-health-check.md (18934b), references/observability/eo-traffic-daily-report.md (24519b), references/observability/README.md (2705b), references/security/domain-blacklist-inspector.md (5057b), references/security/ip-threat-blacklist.md (8666b), references/security/README.md (2634b), references/security/security-template-audit.md (4699b), references/security/security-weekly-report.md (5023b), SKILL.md (3824b), _meta.json (140b)","readmeExcerpt":"Skill: Tencent EdgeOne Owner: tencent-adm Summary: A comprehensive skill for Tencent EdgeOne (Edge Security & Acceleration Platform), covering edge acceleration (DNS, certificates, caching, rule engine, L4 pr... Tags: latest:1.1.1 Version history: v1.1.1 | 2026-06-11T09:16:02.325Z | user Try upgrading tccli before first API call each session (pipx & brew, best-effort) v1.1.0 | 2026-06-03T07:22:12.265Z | user Add --re","codeSnippets":[],"executableExamples":[{"language":"sh","snippet":"tccli <service> <Action> --request-client \"tencent-edgeone-skill/1.1.0 module/<module>\" [other args]"},{"language":"sh","snippet":"pipx upgrade tccli 2>/dev/null || brew upgrade tccli 2>/dev/null || true"},{"language":"sh","snippet":"tccli cvm DescribeRegions --request-client \"tencent-edgeone-skill/1.1.0 module/api\" 2>&1; echo \"EXIT_CODE:$?\""},{"language":"text","snippet":"What does the user want to do?\n│\n├─ \"Generate yesterday's traffic daily report\"\n│  \"Show me the bandwidth peak over the last 24 hours\"\n│  └─ → `eo-traffic-daily-report.md`  🟢 Low Risk · Auto-collect L7/L4 data and generate a Markdown daily report\n│\n├─ \"Check the origin status for example.com\"\n│  \"Is the origin healthy?\" \"Is it a CDN issue or an origin issue?\"\n│  └─ → `eo-origin-health-check.md`  🟢 Low Risk · Origin status code distribution + health ratio + quick root cause analysis\n│\n├─ \"Download the logs for example.com from yesterday afternoon\"\n│  \"Download the last 6 hours of L4 logs\"\n│  └─ → `eo-log-downloader.md`  🟢 Low Risk · Natural language driven offline log download link retrieval\n│\n├─ \"Analyze the logs — too many 502 errors\"\n│  \"Which URIs have the most abnormal requests?\"\n│  \"Show me per-URL download traffic breakdown\"\n│  └─ → `eo-log-analyzer.md`  🟢 Low Risk · Log download + local parsing + pattern recognition + fault inference + traffic aggregation\n│\n└─ Not sure which API to call\n   └─ → `../api/api-discovery.md`"},{"language":"text","snippet":"What does the user want to do?\n│\n├─ \"Generate a security status report for this week\"\n│  \"Check the current security configuration\"\n│  └─ → `security-weekly-report.md`  🟢 Low risk · Sequential data collection, output conclusions first with concise snapshot\n│\n├─ \"Which domains don't have a security template\"\n│  \"Help me check template coverage\"\n│  └─ → `security-template-audit.md`  🟢 Low risk · List unbound domains, prompt for manual confirmation\n│\n├─ \"Check which IP group in example.com's security policy is a blocklist\"\n│  \"Which IP group blocks traffic for this domain\"\n│  └─ → `domain-blacklist-inspector.md`  🟢 Low risk · Read-only query, identify blocklist IP groups\n│\n├─ \"Help me analyze recent attack IP concentration\"\n│  \"Block these IPs\" \"IP ban\"\n│  └─ → `ip-threat-blacklist.md`  🔴 High risk · Mandatory Diff display + double confirmation before write operations, only allowed to write to designated blocklist group\n│\n└─ Not sure which API to call\n   └─ → `../api/api-discovery.md`"},{"language":"text","snippet":"Iterate through user-provided URL list\n  ├─ Check if contains wildcards (* ?)\n  │  ├─ Contains → Prompt user: \"Prefetch doesn't support wildcard URLs, please provide specific file URLs\"\n  │  └─ Doesn't contain → Continue\n  ├─ Check protocol\n  │  ├─ Missing http/https → Prompt user to add protocol\n  │  └─ Has protocol → Continue\n  └─ Add to valid URL list"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: tencent-edgeone-skill\ndescription: A comprehensive skill for Tencent EdgeOne (Edge Security & Acceleration Platform), covering edge acceleration (DNS, certificates, caching, rule engine, L4 proxy, load balancing), edge security (DDoS protection, Web protection, Bot management), edge media (real-time video / image processing), edge development (Edge Functions, EdgeOne Pages), and more. Use this skill whenever a user mentions any EdgeOne / EO-related configuration, operations, querying, or troubleshooting needs.\nversion: 1.1.0\nmetadata:\n  openclaw:\n    requires:\n      bins:\n        - tccli\n        - gunzip\n      anyBins:\n        - curl\n        - wget\n        - jq\n        - python3\n      config:\n        - ~/.tccli/default.credential\n    homepage: https://edgeone.ai\n---\n\n# Tencent EdgeOne Skill\n\nA comprehensive Tencent EdgeOne skill that routes user requests to the appropriate module and loads the corresponding reference document.\n\nKnowledge about EdgeOne APIs, configuration options, limits, and pricing may be outdated.\n**Prefer retrieval over pre-trained knowledge** — the reference files in this skill are only a starting point.\n\n> All tasks **must be completed by calling APIs**.\n> See `references/api/README.md` for API calling conventions, environment checks, etc. **(must be read before starting any task)**.\n\n## Security Red Lines\n\n- **Write operations require user confirmation**: All write operations (Create\\* / Modify\\* / Bind\\* / Delete\\* / Apply\\*, etc.) **must** clearly explain the action and its impact to the user before execution, and wait for user confirmation before calling the API.\n- **Never** ask the user for SecretId / SecretKey\n- **Refuse** any operation that might print credentials\n\n## Interaction & Execution Guidelines\n\n- **Use structured interaction tools**: When asking questions, requesting choices, or confirming operations, if the current environment provides `ask_followup_question` or similar structured interaction tools, you **must** prefer using them (instead of plain-text questions) so that the user can directly click options, reducing ambiguity and improving interaction efficiency. **Do not omit candidate options** — if there are too many to list in full, **must** state the total number first, show the most relevant items, and keep an \"Other (please enter)\" option as the last choice.\n- **Prefer scripts for bulk / repetitive tasks**: For tasks involving large datasets or repetitive operations (batch purge, batch query, loop operations, etc.), prefer writing a script to execute everything at once rather than calling APIs one by one manually.\n\n## Module Entry Points\n\nMatch the user's request to the appropriate module, load its entry document, and follow the instructions.\n\n| Module | Entry | Description |\n|---|---|---|\n| API | `references/api/README.md` | Calling conventions, tool installation, credential configuration, API discovery, zone & domain discovery (ZoneId lookup) |\n| Acceleration | `references/acceleration/REA"},{"path":"references/acceleration/README.md","content":"# EdgeOne Site Acceleration Reference\n\n> **Telemetry note:** You are now in module **`acceleration`**. Every `tccli` call you make from this entry must carry `--request-client \"tencent-edgeone-skill/1.1.0 module/acceleration\"`.\n\nConfiguration and operational guidance for site onboarding, domain management, cache purge/prefetch, and HTTPS certificates.\n\n## Files in This Directory\n\n| File | Risk Level | Trigger Scenarios (User says...) |\n|---|---|---|\n| `zone-onboarding.md` | Medium-High | \"Onboard example.com to EO\" \"Create a new site\" \"Apply for free certificate after onboarding\" |\n| `cache-purge.md` | Medium | \"Purge all cache under /static/\" \"Prefetch these URLs\" \"Check purge task status\" |\n| `cert-manager.md` | Medium | \"Renew certificate that's expiring soon\" \"Bind new certificate to these domains\" \"Check certificate status\" |"},{"path":"references/api/README.md","content":"# EdgeOne API Reference\n\n> **Telemetry note:** You are now in module **`api`**. Every `tccli` call you make from this entry must carry `--request-client \"tencent-edgeone-skill/1.1.0 module/api\"`. See \"Telemetry — RequestClient\" below.\n\nEdgeOne (Edge Security Acceleration Platform) is managed through Tencent Cloud API. Currently uses **tccli** (Tencent Cloud CLI) as the calling tool, with service name **teo**.\n\n## Telemetry — RequestClient (mandatory, best-effort)\n\nEvery `tccli` call you issue while working in this skill — the connectivity probe, `teo` actions, and `dnspod` / `cam` integration calls alike — must carry the `--request-client` flag:\n\n```sh\ntccli <service> <Action> --request-client \"tencent-edgeone-skill/1.1.0 module/<module>\" [other args]\n```\n\n- `<module>` — the entry README you're working from (e.g. `api`, `acceleration`...), or `other` if none fits.\n- Pass the flag per call, so each call carries its own module.\n\n> **Best-effort principle:** telemetry failure must never block or break the user's real task.\n\n## Files in This Directory\n\n| File | Applicable Scenarios |\n|---|---|\n| `install.md` | First-time setup: install tccli (pipx / Homebrew), prepare Python environment |\n| `auth.md` | tccli is installed but missing credentials — browser OAuth login, logout, or multi-account management |\n| `api-discovery.md` | Find API endpoints — search best practices, API lists, and documentation via cloudcache |\n| `zone-discovery.md` | Get zone / domain info: ZoneId lookup, reverse domain lookup, pagination handling |\n| `dnspod-integration.md` | DNSPod hosting access: detect domain hosting status, service authorization, access process |\n\n## Overview\n\n**tccli** is Tencent Cloud's official CLI tool, supporting all cloud API calls.\n\n**Key elements:**\n- **Calling format** — `tccli teo <Action> --request-client \"tencent-edgeone-skill/1.1.0 module/<module>\" [--param value ...]`\n- **Auto credentials** — Browser OAuth authorization is recommended, see `auth.md`\n- **API discovery** — Search best practices, API lists, and documentation online via cloudcache\n\n**Calling conventions:**\n- **Check documentation before calling**: Except for verifying tool availability, you **must** consult the API documentation via `api-discovery.md` before calling any API to confirm the action name, required parameters, and data structures. **Never guess parameters from memory.**\n- If a field's type is a struct, you **must** continue looking up the full field definitions of that struct, recursively until all nested structs have been identified — do not skip or guess.\n\n| Item | Description |\n|---|---|\n| Invocation Form | `tccli teo <Action> --request-client \"tencent-edgeone-skill/1.1.0 module/<module>\" [--param value ...]` |\n| Region | No `--region` by default; add `--region <region>` if user explicitly specifies region |\n| Parameter Format | Non-simple types must be standard JSON |\n| Serial Invocation | tccli has config file competition issues with parallel calls, please call on"},{"path":"references/observability/README.md","content":"# EdgeOne Observability Reference\n\n> **Telemetry note:** You are now in module **`observability`**. Every `tccli` call you make from this entry must carry `--request-client \"tencent-edgeone-skill/1.1.0 module/observability\"`.\n\nOperational guides for traffic daily report generation, origin health inspection, offline log download, and log analysis.\n\n## Quick Decision Tree\n\n```\nWhat does the user want to do?\n│\n├─ \"Generate yesterday's traffic daily report\"\n│  \"Show me the bandwidth peak over the last 24 hours\"\n│  └─ → `eo-traffic-daily-report.md`  🟢 Low Risk · Auto-collect L7/L4 data and generate a Markdown daily report\n│\n├─ \"Check the origin status for example.com\"\n│  \"Is the origin healthy?\" \"Is it a CDN issue or an origin issue?\"\n│  └─ → `eo-origin-health-check.md`  🟢 Low Risk · Origin status code distribution + health ratio + quick root cause analysis\n│\n├─ \"Download the logs for example.com from yesterday afternoon\"\n│  \"Download the last 6 hours of L4 logs\"\n│  └─ → `eo-log-downloader.md`  🟢 Low Risk · Natural language driven offline log download link retrieval\n│\n├─ \"Analyze the logs — too many 502 errors\"\n│  \"Which URIs have the most abnormal requests?\"\n│  \"Show me per-URL download traffic breakdown\"\n│  └─ → `eo-log-analyzer.md`  🟢 Low Risk · Log download + local parsing + pattern recognition + fault inference + traffic aggregation\n│\n└─ Not sure which API to call\n   └─ → `../api/api-discovery.md`\n```\n\n## Prerequisites\n\nAll operations require API calls via tccli. Before first use, complete the following:\n\n1. **Tool Setup** — Read `../api/README.md` to install tccli and configure credentials\n2. **Get ZoneId** — Read `../api/zone-discovery.md` to obtain the zone ID\n\n## Files in This Directory\n\n| File | Risk Level | Core Trigger Scenario |\n|---|---|---|\n| `eo-traffic-daily-report.md` | 🟢 Low Risk | Query L7/L4 traffic trends daily and generate a Markdown report with bandwidth peak, request volume, and Top domains/regions |\n| `eo-origin-health-check.md` | 🟢 Low Risk | Query origin status code distribution and origin health ratio for quick origin fault root cause analysis |\n| `eo-log-downloader.md` | 🟢 Low Risk | Describe time range and domain in natural language to automatically retrieve offline log download links |\n| `eo-log-analyzer.md` | 🟢 Low Risk | Automatically download and parse logs locally, extract anomaly details, provide pattern recognition conclusions with fault inference, or aggregate traffic by domain/URL |\n\n## Reference Links\n\n- [EdgeOne Product Documentation](https://edgeone.ai/document/56978)\n- [EdgeOne API Documentation](https://edgeone.ai/document/50454)\n- API Usage Guide: `../api/README.md`"},{"path":"references/security/README.md","content":"# EdgeOne Security Protection Reference\n\n> **Telemetry note:** You are now in module **`security`**. Every `tccli` call you make from this entry must carry `--request-client \"tencent-edgeone-skill/1.1.0 module/security\"`.\n\nConfiguration and operations guide for security policy configuration snapshots, template coverage audits, and domain IP group blocklist identification.\n\n## Quick Decision Tree\n\n```\nWhat does the user want to do?\n│\n├─ \"Generate a security status report for this week\"\n│  \"Check the current security configuration\"\n│  └─ → `security-weekly-report.md`  🟢 Low risk · Sequential data collection, output conclusions first with concise snapshot\n│\n├─ \"Which domains don't have a security template\"\n│  \"Help me check template coverage\"\n│  └─ → `security-template-audit.md`  🟢 Low risk · List unbound domains, prompt for manual confirmation\n│\n├─ \"Check which IP group in example.com's security policy is a blocklist\"\n│  \"Which IP group blocks traffic for this domain\"\n│  └─ → `domain-blacklist-inspector.md`  🟢 Low risk · Read-only query, identify blocklist IP groups\n│\n├─ \"Help me analyze recent attack IP concentration\"\n│  \"Block these IPs\" \"IP ban\"\n│  └─ → `ip-threat-blacklist.md`  🔴 High risk · Mandatory Diff display + double confirmation before write operations, only allowed to write to designated blocklist group\n│\n└─ Not sure which API to call\n   └─ → `../api/api-discovery.md`\n```\n\n## Prerequisites\n\nAll operations require calling APIs via tccli. Before first use, complete the following:\n\n1. **Tool check** — Read `../api/README.md` to complete tccli installation and credential configuration\n2. **Get ZoneId** — Read `../api/zone-discovery.md` to obtain the zone ID\n\n## Files in This Directory\n\n| File | Risk Level | Core Trigger Scenario |\n|---|---|---|\n| `security-weekly-report.md` | 🟢 Low risk | Periodically generate security configuration snapshots to detect abnormal policy changes |\n| `security-template-audit.md` | 🟢 Low risk | Audit security policy template coverage, find domains without bound templates |\n| `domain-blacklist-inspector.md` | 🟢 Low risk | Query security policies associated with a specific domain, identify IP groups serving as blocklists |\n| `ip-threat-blacklist.md` | 🔴 High risk | Analyze L7 high-concentration threat IPs, execute IP blocklist banning (write operations require double confirmation) |\n\n## Reference Links\n\n- [EdgeOne Product Documentation](https://edgeone.ai/document)\n- [EdgeOne API Documentation](https://edgeone.ai/document/50454)\n- API Calling Guide: `../api/README.md`"}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":1896,"uniquenessScore":43,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-11T14:16:57.516Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-11T14:16:57.516Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-11T17:44:13.563Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}