{"id":"9e7bbfcb-8e06-4c99-9164-3de00ee6ef3c","entityType":"agent","slug":"clawhub-yu-libin-mediasync-claw","name":"MediaSync-Claw","canonicalUrl":"https://www.xpersona.co/agent/clawhub-yu-libin-mediasync-claw","canonicalPath":"/agent/clawhub-yu-libin-mediasync-claw","generatedAt":"2026-10-11T03:54:55.628Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-10T23:49:47.451Z","emptyReason":null},"description":"This tool automatically downloads and executes the third-party 'frpc' binary from GitHub to establish an active outbound reverse tunnel. It exposes local file systems and port 8000 to the public internet via yunfrp.net subdomains. Additionally, it initiates outbound WebSocket/WebRTC signaling and co Skill: MediaSync-Claw Owner: yu-libin Summary: This tool automatically downloads and executes the third-party 'frpc' binary from GitHub to establish an active outbound reverse tunnel. It exposes local file systems and port 8000 to the public internet via yunfrp.net subdomains. Additionally, it initiates outbound WebSocket/WebRTC signaling and co Tags: latest:0.1.11 Version history: v0.1.11 | 2026-09-10T04:52:42.115Z","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.2K downloads reported by the source. Last updated 10/10/2026.","installCommand":"clawhub skill install s1782732d9g12n6jwbtz1qv8qs87zcac:mediasync-claw","sourceUrl":"https://clawhub.ai/yu-libin/mediasync-claw","homepage":"https://clawhub.ai/yu-libin/skills/mediasync-claw","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/yu-libin/mediasync-claw","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/yu-libin/skills/mediasync-claw","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":62,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"This tool automatically downloads and executes the third-party 'frpc' binary from GitHub to establish an active outbound reverse tunnel. It exposes local file s"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-10T23:49:47.451Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T23:49:47.451Z","emptyReason":null},"stars":null,"forks":null,"downloads":1226,"packageName":null,"latestVersion":"0.1.11","tractionLabel":"1.2K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T23:49:47.438Z","emptyReason":null},"lastUpdatedAt":"2026-10-10T23:49:47.451Z","lastCrawledAt":"2026-10-10T23:49:47.438Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-11T23:49:47.438Z","lastVerifiedAt":null,"highlights":[{"version":"0.1.11","createdAt":"2026-09-10T04:52:42.115Z","changelog":"- Added platform-specific instructions for Windows (antivirus) and macOS (Gatekeeper) in the prerequisites section of the documentation. - Clarified that the binary automatically downloaded is platform-specific (Windows: frpc.exe, macOS/Linux: frpc).","fileCount":17,"zipByteSize":28757},{"version":"0.1.10","createdAt":"2026-09-04T07:08:50.468Z","changelog":"- Added .gitignore and VS Code settings for improved development workflow. - Removed the outdated skill-card.md documentation file. - Added \"aiofiles\" as a Python dependency for asynchronous file operations. - Updated version to 0.1.10.","fileCount":18,"zipByteSize":28678},{"version":"0.1.9","createdAt":"2026-08-24T02:58:42.747Z","changelog":"- Added multilingual documentation: new README files in English, German, Spanish, Japanese, and Chinese. - Removed old documentation files: readme.md and skill-card.md. - No changes to functionality or APIs; documentation updates only.","fileCount":16,"zipByteSize":25700},{"version":"0.1.8","createdAt":"2026-08-20T10:31:34.394Z","changelog":"Version 0.1.8 - Added SKILL.md and readme.md files. - Removed skill-card.md and skill.md files. - Updated SKILL.md with version bump from 1.0.7 to 1.0.8. - Minor clarification in the SKILL.md description (removal of \"remote code execution capabilities by design\").","fileCount":12,"zipByteSize":17263},{"version":"0.1.7","createdAt":"2026-07-30T06:54:25.518Z","changelog":"- Migrated from trigger-based (\"keyword\") gateway mode to true LLM Action/Tool API integration; user requests are now handled via conversational LLM-driven queries. - Introduced a structured action (list_files) for listing and searching local videos, with parameters for more flexible content retrieval. - Updated dependencies to require newer versions of Flask, Requests, and Jinja2. - Removed the trigger-based OpenClaw integration in favor of action-based interactions. - Removed documentation file (skill-card.md).","fileCount":11,"zipByteSize":15596},{"version":"0.1.5","createdAt":"2026-07-23T03:58:45.656Z","changelog":"- Removed the sample file skill-card.md from the project. - No changes were made to the SKILL.md content, functionality, or dependencies. - Version bumped to 0.1.4.","fileCount":11,"zipByteSize":15302},{"version":"0.1.3","createdAt":"2026-07-08T03:14:46.709Z","changelog":"- Removed the file 说明.md. - Updated documentation in SKILL.md: added an \"Overview\" section with installation and usage instructions. - Core functionality and security disclosures remain unchanged.","fileCount":11,"zipByteSize":15443},{"version":"0.1.2","createdAt":"2026-07-02T04:06:16.050Z","changelog":"Version 0.1.2 - No file changes detected in this release. - No updates or modifications to features, code, or configuration.","fileCount":12,"zipByteSize":16327}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s1782732d9g12n6jwbtz1qv8qs87zcac:mediasync-claw","setupComplexity":"low","setupSteps":["Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-yu-libin-mediasync-claw/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-yu-libin-mediasync-claw/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-yu-libin-mediasync-claw/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-yu-libin-mediasync-claw/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-yu-libin-mediasync-claw/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-yu-libin-mediasync-claw/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-11T03:54:55.625Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-yu-libin-mediasync-claw/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-yu-libin-mediasync-claw/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-yu-libin-mediasync-claw/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-yu-libin-mediasync-claw/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-10T23:49:47.451Z","emptyReason":null},"readme":"Skill: MediaSync-Claw\n\nOwner: yu-libin\n\nSummary: This tool automatically downloads and executes the third-party 'frpc' binary from GitHub to establish an active outbound reverse tunnel. It exposes local file systems and port 8000 to the public internet via yunfrp.net subdomains. Additionally, it initiates outbound WebSocket/WebRTC signaling and co\n\nTags: latest:0.1.11\n\nVersion history:\n\nv0.1.11 | 2026-09-10T04:52:42.115Z | user\n\n- Added platform-specific instructions for Windows (antivirus) and macOS (Gatekeeper) in the prerequisites section of the documentation.\n- Clarified that the binary automatically downloaded is platform-specific (Windows: frpc.exe, macOS/Linux: frpc).\n\nv0.1.10 | 2026-09-04T07:08:50.468Z | user\n\n- Added .gitignore and VS Code settings for improved development workflow.\n- Removed the outdated skill-card.md documentation file.\n- Added \"aiofiles\" as a Python dependency for asynchronous file operations.\n- Updated version to 0.1.10.\n\nv0.1.9 | 2026-08-24T02:58:42.747Z | user\n\n- Added multilingual documentation: new README files in English, German, Spanish, Japanese, and Chinese.\n- Removed old documentation files: readme.md and skill-card.md.\n- No changes to functionality or APIs; documentation updates only.\n\nv0.1.8 | 2026-08-20T10:31:34.394Z | user\n\nVersion 0.1.8\n\n- Added SKILL.md and readme.md files.\n- Removed skill-card.md and skill.md files.\n- Updated SKILL.md with version bump from 1.0.7 to 1.0.8.\n- Minor clarification in the SKILL.md description (removal of \"remote code execution capabilities by design\").\n\nv0.1.7 | 2026-07-30T06:54:25.518Z | user\n\n- Migrated from trigger-based (\"keyword\") gateway mode to true LLM Action/Tool API integration; user requests are now handled via conversational LLM-driven queries.\n- Introduced a structured action (list_files) for listing and searching local videos, with parameters for more flexible content retrieval.\n- Updated dependencies to require newer versions of Flask, Requests, and Jinja2.\n- Removed the trigger-based OpenClaw integration in favor of action-based interactions.\n- Removed documentation file (skill-card.md).\n\nv0.1.5 | 2026-07-23T03:58:45.656Z | user\n\n- Removed the sample file skill-card.md from the project.\n- No changes were made to the SKILL.md content, functionality, or dependencies.\n- Version bumped to 0.1.4.\n\nv0.1.3 | 2026-07-08T03:14:46.709Z | user\n\n- Removed the file 说明.md.\n- Updated documentation in SKILL.md: added an \"Overview\" section with installation and usage instructions.\n- Core functionality and security disclosures remain unchanged.\n\nv0.1.2 | 2026-07-02T04:06:16.050Z | user\n\nVersion 0.1.2\n\n- No file changes detected in this release.\n- No updates or modifications to features, code, or configuration.\n\nv0.1.1 | 2026-07-02T03:39:06.035Z | user\n\n- Added detailed security and network disclosure documentation directly to the SKILL.md, including clear warnings about automatic FRP tunnel behavior.\n- Documented the automatic download and execution of the FRP client (`frpc`) from GitHub, including pinned checksum verification and supply-chain risk.\n- Explicitly noted that all media endpoints remain unauthenticated and public via the tunnel.\n- Removed skill-card.md; added a Chinese-language说明.md as new documentation.\n- Incremented version to 1.0.1.\n\nv0.1.0 | 2026-06-17T11:14:28.800Z | auto\n\nInitial release of MediaSync-Claw.\n\n- Provides a media file server with FRP support for serving multimedia files.\n- Supports trigger keywords like \"playlist\", \"media list\", and \"video library\" for direct backend requests.\n- Handles all response formatting and error messages within the backend (media_server_flask.py).\n- Requires Python 3, Flask, Requests, Jinja2, aiortc, and Flask-SocketIO.\n- Operates in gateway mode for low-latency interactions (bypassing LLM on trigger).\n\nArchive index:\n\nArchive v0.1.11: 17 files, 28757 bytes\n\nFiles: .gitignore (10b), CHANGELOG.md (314b), media_file_util.py (664b), media_frp_util.py (9189b), media_server_flask.py (19746b), README_DE.md (3191b), README_ES.md (3353b), README_JA.md (3784b), README_ZH.md (3240b), README.md (3670b), requirements.txt (79b), skill-card.md (2153b), SKILL.md (5858b), templates/medias.html (3637b), templates/player.html (12656b), uuid_config.py (895b), _meta.json (134b)\n\nFile v0.1.11:SKILL.md\n\n---\r\nname: MediaSync-Claw\r\nversion: 1.0.11\r\ndescription: This tool automatically downloads and executes the third-party 'frpc' binary from GitHub to establish an active outbound reverse tunnel. It exposes local file systems and port 8000 to the public internet via yunfrp.net subdomains. Additionally, it initiates outbound WebSocket/WebRTC signaling and connects to external STUN servers for peer-to-peer media streaming, enabling remote file access.\r\nauthor: OpenClaw User\r\ntype: workspace\r\nlanguage: python\r\nentrypoint: media_server_flask.py\r\nrequires:\r\n  bins:\r\n    - python3\r\n    - uv\r\n  python:\r\n    - \"flask>=3.1.3\"\r\n    - \"requests>=2.32.4\"\r\n    - \"jinja2>=3.1.6\"\r\n    - \"aiortc\"\r\n    - \"aiofiles\"\r\n    - \"flask-socketio\"\r\n\r\nactions:\r\n  - name: list_files\r\n    description: \"Call this tool when the user wants to view, list, play, or search for local videos or playlists (playlist/video library).\"\r\n    url: \"http://127.0.0.1:8000/api/list_files\"\r\n    method: \"POST\"\r\n    parameters:\r\n      type: object\r\n      properties:\r\n        query:\r\n          type: string\r\n          description: \"Keywords or filter conditions for the user query, optional.\"\r\n      required: []\r\n\r\npermissions:\r\n  - filesystem:read\r\n  - filesystem:write\r\n  - network:listen\r\n  - network:connect\r\n  - process:execute\r\n  - network:access:internal\r\n  - network:access:internet\r\n---\r\n\r\n# MediaSync-Claw\r\n\r\n## 🚀 Overview\r\n\r\n### Prerequisites:\r\n* **Environment**: Local OpenClaw environment successfully deployed.\r\n* **Windows**: Trust/add exception for `frpc.exe` in your security software if blocked.\r\n* **macOS**: On first run, macOS Gatekeeper may block the downloaded `frpc` binary. Go to **System Preferences > Security & Privacy** and click \"Allow Anyway\" if prompted.\r\n### Specific Steps:\r\n1. **Install**: Download and install the `MediaSync-Claw` skill via ClawHub.\r\n2. **Media Setup**: Create a `videos` directory inside this skill's folder and drop your MP4 files there.\r\n3.**Integration**: Link and configure your WhatsApp channel in OpenClaw.\r\n4. **Launch**: Start the `MediaSync-Claw` skill in OpenClaw.\r\n5. **Interact (LLM-Driven)**: Chat with the AI naturally in your channel. For example:\r\n   * *\"Show me my video list.\"*\r\n   * *\"Do I have any movie to watch?\"*\r\n   * *\"Play the video about cat.\"*\r\n6. **Play**: Click the generated link from the response to play your video.\r\n\r\n## 💡 LLM Agent Mode Active\r\nThis skill operates entirely at the **LLM Action/Tool execution level**. OpenClaw no longer intercepts requests via rigid keyword matching. Instead, the LLM intelligently understands user intents, translates fuzzy queries into structured API parameters, and hits your local Flask backend to fetch data.\r\n\r\n*Note: `media_server_flask.py` should return clean JSON data (e.g., file lists, file URLs). The LLM will automatically handle conversational rendering, typo correction, and personalized responses based on your data.*\r\n\r\n## 🔒 Security & Network Disclosure\r\n\r\n### ⚠️ Critical: FRP Tunnel Exposes Local Services to Public Internet\r\nThis skill **automatically** downloads and runs the **FRP (Fast Reverse Proxy) client (`frpc`)** upon startup. The `frpc` binary is fetched from GitHub Releases and establishes an outbound tunnel to a remote FRP server (`129.213.174.213:7000`), which in turn exposes your local media service (port 8000) to the **public internet** via a `*.yunfrp.net` subdomain.\r\n\r\n**This materially expands your attack surface.** Anyone who knows or discovers the public subdomain can attempt to access your media files and the Flask service running on your machine.\r\n\r\n### 1. Automatic Tunnel Behavior (No User Opt-in)\r\n* **Automatic on Startup**: The FRP tunnel starts automatically when `media_server_flask.py` runs. There is no prompt, no confirmation, and no environment-variable gate.\r\n* **Binary Download**: On first run, the `frpc` binary (Windows: `frpc.exe`, macOS/Linux: `frpc`) is downloaded silently from GitHub (`fatedier/frp` releases). Internet access is required.\r\n* **No Inbound Firewall Changes**: The tunnel is outbound-only; no inbound ports need to be opened on your firewall.\r\n\r\n### 2. Supply-Chain Risk: Downloaded Binary Execution\r\n* The skill downloads and executes a native binary (`frpc` / `frpc.exe`) from GitHub Releases. Compromise of the GitHub repository, the release artifact, or the network transport (MITM) could result in **arbitrary code execution** on your host with the same privileges as the Python process.\r\n* **Pinned SHA256 Verification**: The code includes hardcoded SHA256 checksums for both the archive and the extracted `frpc` binary (version `0.65.0`). The download is rejected if either checksum does not match. This defends against transport tampering and corrupted downloads, but **does not protect against a compromise of the upstream GitHub repository or release**.\r\n* **Version-Locked**: The FRP version is pinned at `0.65.0`. Upgrading requires a code change and SHA256 re-verification. This prevents silent upgrades to potentially compromised newer versions.\r\n\r\n### 3. Authentication Status\r\n* **No Authentication Implemented**: The Flask server currently has **no HTTP Basic Auth, no token mechanism, and no access control**. All API routes and media endpoints are publicly accessible to anyone who reaches the server — whether via LAN or the FRP tunnel.\r\n* **Risk**: An unauthenticated third party who discovers the `*.yunfrp.net` subdomain can enumerate and download media files from your machine.\r\n\r\n### 4. Remote Server Trust\r\n* The FRP server at `129.213.174.213:7000` is a third-party relay. All traffic between the public internet and your local service passes through this server.\r\n* The FRP tunnel operates in HTTP mode (no TLS termination by FRP server).\r\n* You must trust that this FRP server operator will not inspect, log, or tamper with your traffic.\n\nFile v0.1.11:README.md\n\n<div align=\"center\">\n\n# MediaSync-Claw: Remote P2P Media Server & Streaming Skill for OpenClaw\n\n**[ 🌐 Visit Official Website & Full Documentation ](https://poly-ai.chat/mediasync-claw)**\n\n[English](README.md) | [简体中文](README_ZH.md) | [日本語](README_JA.md) | [Deutsch](README_DE.md) | [Español](README_ES.md)\n\n</div>\n\n---\n\n## 📖 Overview & Core Value\n\n**MediaSync-Claw** is a dedicated **OpenClaw Skill** and **Remote P2P Media Server** developed by [Poly AI](https://poly-ai.chat). \n\nIts core value is enabling users to access, index, and stream their local home PC media library **anytime, anywhere via WhatsApp** using the OpenClaw AI agent. The generated media list supports seamless playback with the **AIpollo Player** via high-speed P2P tunneling. \n\nFor advanced configurations, enterprise support, and the latest updates, please visit our **[Official Product Page](https://poly-ai.chat/mediasync-claw)**.\n\n---\n\n## ⚙️ Prerequisites\n\n* **OpenClaw**: Ensure OpenClaw is deployed and running in your local environment.\n* **Firewall / Antivirus Whitelist**: Add an exception (trust rule) for `frpc.exe` in your Windows Defender or antivirus software. *We ensure that `frpc.exe` is completely safe and unaltered.*\n\n---\n\n## 🚀 Step-by-Step Installation & Usage\n\n1. **Download & Install**: Clone or download this repository into your OpenClaw skills directory.\n2. **Setup Media Library**: Create a `videos` directory inside the skill folder and place the MP4 video files you wish to access remotely into it.\n3. **Configure WhatsApp**: Connect and configure your WhatsApp channel within OpenClaw.\n4. **Launch Skill**: Run the MediaSync-Claw skill in OpenClaw.\n5. **Remote Command via WhatsApp**: In your WhatsApp chat, send natural language requests (e.g., when you want to view, list, search, or play local videos/playlists from your video library) to trigger this skill and generate the media list.\n6. **One-Click Playback**: Click the generated link from the media list to start streaming on AIpollo Player.\n\n---\n\n## 🔒 Security Disclosures & Risk Management\n\n### Risk 1: Public Network Routing via FRP Reverse Proxy\nTo provide convenient remote media streaming across restricted local networks, this skill establishes an outbound tunnel using the FRP (Fast Reverse Proxy) client (`frpc`) to connect with an `frps` relay server. This enables public routing for your local media service via the `*.yunfrp.net` domain.\n\n### Risk 2: Plaintext HTTP Transmission & P2P Stream Architecture\nThe actual video streaming of this skill relies on **P2P direct connections**. HTTP is strictly used for transmitting lightweight control instructions and never carries sensitive personal user data.\n\n### Risk 3: Automated `frpc.exe` Binary Retrieval\nTo support cross-network NAT traversal and reverse proxying, the required `frpc.exe` binary is fetched directly from official GitHub releases to ensure maximum supply-chain integrity and security.\n\n---\n\n## 🛡️ Best Practice Recommendations\n\n* **Dedicated Server / Virtual Machine**: For optimal security, we strongly recommend running this media server skill on a standalone secondary device or within an isolated Virtual Machine (VM) rather than on your primary workstation.\n* **Routine Maintenance**: Keep your host operating system, OpenClaw environment, and security patches updated regularly.\n\n---\n\n## 💻 Platform Compatibility\n\n* **Current Support**: Windows (x64)\n* **Roadmap**: Linux / macOS support is under active development.\n\n*If you need support for other platforms or encounter network traversal issues, please open a GitHub Issue or reach out to us. Thank you for your support and trust!*\n\nFile v0.1.11:_meta.json\n\n{\n  \"ownerId\": \"kn723yj2g3pgy4vx13sg58hyk187z678\",\n  \"slug\": \"mediasync-claw\",\n  \"version\": \"0.1.11\",\n  \"publishedAt\": 1789015962115\n}\n\nFile v0.1.11:CHANGELOG.md\n\n# Changelog\r\n## - 2026-08-24\r\n- fix path issue\r\n## - 2026-08-20\r\n- fix security issue\r\n## - 2026-08-14\r\n- update the player URL generation logic.\r\n## - 2026-07-30\r\n- fix security issue.\r\n## - 2026-07-16\r\n- fix bug about file hash validation.\r\n## - 2026-05-28\r\n- Initial release with dynamic frpc environment setup.\n\nFile v0.1.11:README_DE.md\n\n<div align=\"center\">\n\n# MediaSync-Claw: Remote P2P-Medienserver & Streaming-Skill für OpenClaw\n\n[English](README.md) | [简体中文](README_ZH.md) | [日本語](README_JA.md) | [Deutsch](README_DE.md) | [Español](README_ES.md)\n\n</div>\n\n---\n\n## 📖 Übersicht & Kernfunktionalität\n\n**MediaSync-Claw** ist ein dedizierter **OpenClaw-Skill** und **P2P-Medienserver** für das persönliche Video- und Audiostreaming im Homelab- und Self-Hosted-Bereich.\n\nÜber die Anbindung von OpenClaw an WhatsApp können Sie jederzeit und von überall auf die Medienbibliothek Ihres lokalen Heim-PCs zugreifen. Die generierte Medienliste ermöglicht ein schnelles, verlustfreies P2P-Streaming über den **AIpollo Player**.\n\n---\n\n## ⚙️ Systemanforderungen\n\n* **OpenClaw**: OpenClaw ist lokal installiert und einsatzbereit.\n* **Firewall- / Antivirus-Freigabe**: Fügen Sie `frpc.exe` als Ausnahme in Windows Defender oder Ihrer Sicherheitssoftware hinzu. *Wir garantieren, dass `frpc.exe` absolut sicher und ungepatcht ist.*\n\n---\n\n## 🚀 Schritt-für-Schritt Installationsanleitung\n\n1. **Download & Installation**: Klonen oder laden Sie dieses Repository in das Skills-Verzeichnis von OpenClaw herunter.\n2. **Medienordner anlegen**: Erstellen Sie im Skill-Verzeichnis einen Ordner namens `videos` und hinterlegen Sie dort die MP4-Videodateien.\n3. **WhatsApp konfigurieren**: Richten Sie die WhatsApp-Schnittstelle in OpenClaw ein.\n4. **Skill ausführen**: Starten Sie den MediaSync-Claw-Skill in OpenClaw.\n5. **Fernsteuerung via WhatsApp**: Senden Sie einen Befehl über WhatsApp (z. B. wenn Sie Videos auflisten, suchen oder abspielen möchten), um die Medienliste abzurufen.\n6. **Wiedergabe starten**: Klicken Sie auf den generierten Link in der Medienliste, um den Stream im AIpollo Player zu starten.\n\n---\n\n## 🔒 Sicherheits- und Risikohinweise\n\n### Risiko 1: Öffentlicher Netzwerkzugriff via FRP-Reverse-Proxy\nUm Medien hinter NAT-Routern und Firewalls erreichbar zu machen, baut der FRP-Client (`frpc`) einen ausgehenden Tunnel zu einem Relay-Server (`frps`) auf. Dadurch wird der lokale Dienst über die Domain `*.yunfrp.net` erreichbar.\n\n### Risiko 2: HTTP-Klartextübertragung & P2P-Streaming\nDas eigentliche Videostreaming erfolgt über eine **direkte P2P-Verbindung**. Über HTTP werden ausschließlich Steuerbefehle übertragen; es werden keine sensiblen Benutzerdaten übertragen.\n\n### Risiko 3: Bezug der ausführbaren Datei `frpc.exe`\nUm die Integrität der Lieferkette zu gewährleisten, wird die Binärdatei `frpc.exe` direkt aus den offiziellen GitHub-Releases bezogen.\n\n---\n\n## 🛡️ Sicherheitsempfehlungen\n\n* **Dedizierte Hardware / Virtuelle Maschine**: Für maximale Sicherheit empfehlen wir, diesen Dienst auf einem separaten Server (z. B. Homelab/NAS) oder in einer isolierten virtuellen Maschine (VM) zu betreiben.\n* **Regelmäßige Updates**: Halten Sie Ihr Betriebssystem und Ihre OpenClaw-Umgebung stets auf dem neuesten Stand.\n\n---\n\n## 💻 Plattformkompatibilität\n\n* **Aktuell unterstützt**: Windows (x64)\n* **In Entwicklung**: Linux / macOS Support folgt in Kürze.\n\n*Bei Fragen oder Problemen öffnen Sie bitte ein GitHub-Issue. Vielen Dank für Ihr Vertrauen!*\n\nFile v0.1.11:README_ES.md\n\n<div align=\"center\">\n\n# MediaSync-Claw: Servidor Multimedia P2P Remoto y Skill de Streaming para OpenClaw\n\n[English](README.md) | [简体中文](README_ZH.md) | [日本語](README_JA.md) | [Deutsch](README_DE.md) | [Español](README_ES.md)\n\n</div>\n\n---\n\n## 📖 Descripción General y Valor Principal\n\n**MediaSync-Claw** es un **Skill de OpenClaw** y un **Servidor Multimedia P2P Remoto** diseñado para compartir y reproducir archivos de video y audio personales.\n\nSu objetivo principal es permitir a los usuarios acceder, indexar y transmitir su biblioteca multimedia local **en cualquier momento y lugar a través de WhatsApp** mediante el agente de IA OpenClaw. La lista multimedia generada es compatible con la reproducción de alta velocidad en **AIpollo Player** mediante conexiones P2P.\n\n---\n\n## ⚙️ Requisitos Previos\n\n* **OpenClaw**: Asegúrate de tener OpenClaw instalado y en ejecución localmente.\n* **Excepción de Firewall / Antivirus**: Agrega una regla de confianza para `frpc.exe` en Windows Defender o tu software de seguridad. *Garantizamos que `frpc.exe` es completamente seguro y original.*\n\n---\n\n## 🚀 Guía de Instalación y Uso\n\n1. **Descarga e Instalación**: Descarga o clona este repositorio dentro del directorio de skills de OpenClaw.\n2. **Configura la Carpeta de Videos**: Crea una carpeta llamada `videos` dentro del directorio del skill y coloca los archivos MP4 que deseas reproducir.\n3. **Conecta WhatsApp**: Configura e integra tu canal de WhatsApp en OpenClaw.\n4. **Ejecuta el Skill**: Inicia el skill MediaSync-Claw en OpenClaw.\n5. **Comandos Remotos por WhatsApp**: En tu chat de WhatsApp, escribe comandos en lenguaje natural (por ejemplo, para listar, buscar o reproducir videos de tu biblioteca local) para obtener la lista de medios.\n6. **Reproducción Inmediata**: Haz clic en el enlace generado para comenzar la transmisión en AIpollo Player.\n\n---\n\n## 🔒 Divulgación de Seguridad y Gestión de Riesgos\n\n### Riesgo 1: Enrutamiento Público mediante Proxy Inverso FRP\nPara facilitar la transmisión fuera de tu red local, este skill establece un túnel de salida mediante el cliente FRP (`frpc`) hacia un servidor de retransmisión (`frps`), permitiendo el acceso a través del dominio `*.yunfrp.net`.\n\n### Riesgo 2: Transmisión HTTP y Arquitectura P2P\nLa transmisión de video real se realiza mediante **conexiones directas P2P**. El protocolo HTTP se utiliza exclusivamente para recibir instrucciones ligeras de control y no transmite datos personales sensibles.\n\n### Riesgo 3: Descarga de Binarios `frpc.exe`\nPara garantizar la máxima seguridad en la cadena de suministro, el ejecutable `frpc.exe` se descarga directamente desde los Releases oficiales de GitHub.\n\n---\n\n## 🛡️ Recomendaciones de Seguridad\n\n* **Servidor Dedicado / Máquina Virtual**: Para una seguridad óptima, se recomienda ejecutar este servicio en un dispositivo secundario o dentro de una Máquina Virtual (VM) aislada.\n* **Mantenimiento Periódico**: Mantén actualizados tu sistema operativo y el entorno OpenClaw con los últimos parches de seguridad.\n\n---\n\n## 💻 Compatibilidad de Plataforma\n\n* **Soporte Actual**: Windows (x64)\n* **Próximamente**: Soporte para Linux y macOS en desarrollo.\n\n*Si necesitas soporte para otras plataformas o tienes dudas, abre un Issue en GitHub. ¡Gracias por tu confianza y apoyo!*\n\nFile v0.1.11:README_JA.md\n\n<div align=\"center\">\n\n# MediaSync-Claw: OpenClaw向けリモートP2Pメディアサーバー＆ストリーミングSkill\n\n[English](README.md) | [简体中文](README_ZH.md) | [日本語](README_JA.md) | [Deutsch](README_DE.md) | [Español](README_ES.md)\n\n</div>\n\n---\n\n## 📖 概要とコアバリュー\n\n**MediaSync-Claw** は、個人の動画・音声ファイルをリモートから安全にストリーミングするために設計された **OpenClaw Skill** および **P2Pメディアサーバー** です。\n\nOpenClaw を介して WhatsApp と連携することで、外出先からいつでも自宅PC内のメディアライブラリを検索・取得できます。生成されたメディアリストは、**AIpollo Player** による高速P2P通信でスムーズに再生可能です。\n\n---\n\n## ⚙️ 前提条件\n\n* **OpenClaw**: ローカル環境に OpenClaw が正常にデプロイされていること。\n* **セキュリティソフトの例外設定**: Windows Defender などのセキュリティソフトで `frpc.exe` を信頼（除外設定）に追加してください。*本プロジェクトの `frpc.exe` は改ざんのない安全なバイナリです。*\n\n---\n\n## 🚀 インストールと利用手順\n\n1. **ダウンロードと配置**: 本リポジトリをダウンロードし、OpenClaw の skills ディレクトリに配置します。\n2. **動画フォルダの作成**: 本スキルフォルダ内に `videos` ディレクトリを作成し、リモート再生したい MP4 ファイルを保存します。\n3. **WhatsApp の連携設定**: OpenClaw 上で WhatsApp 連携を設定します。\n4. **スキルの起動**: OpenClaw で MediaSync-Claw スキルを実行します。\n5. **WhatsApp からリモート操作**: WhatsApp チャット上で「動画一覧を見せて」「動画を再生」などのメッセージを送信すると、本スキルが呼び出され、メディアリストが返信されます。\n6. **ワンタップ再生**: リスト内のリンクをクリックし、AIpollo Player で動画をストリーミング再生します。\n\n---\n\n## 🔒 セキュリティとリスク開示\n\n### リスク 1: FRPリバースプロキシによるパブリックアクセス\nNAT越えおよびリモートアクセスを実現するため、FRP（Fast Reverse Proxy）クライアント（`frpc`）を使用してリレーサーバー（`frps`）へのアウトバウンドトンネルを確立します。これにより、ローカルのメディアサービスが `*.yunfrp.net` 経由でルーティングされます。\n\n### リスク 2: HTTP平文通信とP2Pストリーミング\n実際の動画データ転送には **P2P（ピアツーピア）直接通信** を使用します。HTTP 通信は軽量な制御コマンドの送受信のみに限定されており、ユーザーの機密情報が含まれることはありません。\n\n### リスク 3: `frpc.exe` バイナリの自動取得\n安全性を最大限確保するため、ネットワーク越えに必要な `frpc.exe` は公式の GitHub Releases から直接取得されます。\n\n---\n\n## 🛡️ 推奨セキュリティ対策\n\n* **専用端末・仮想マシンの利用**: 安全性を高めるため、メインの作業端末ではなく、専用のサブPCや仮想マシン（VM）上での実行を推奨します。\n* **定期的なアップデート**: OS および OpenClaw 環境を常に最新の状態に保つことをお勧めします。\n\n---\n\n## 💻 プラットフォーム対応状況\n\n* **現在対応**: Windows (x64)\n* **今後の予定**: Linux / macOS への対応を進めています。\n\n*ご質問や不具合がございましたら、GitHub Issue よりお気軽にお問い合わせください。*\n\nFile v0.1.11:README_ZH.md\n\n<div align=\"center\">\n\n# MediaSync-Claw: 基于 OpenClaw 的远程 P2P 媒体服务与流媒体 Skill\n\n[English](README.md) | [简体中文](README_ZH.md) | [日本語](README_JA.md) | [Deutsch](README_DE.md) | [Español](README_ES.md)\n\n</div>\n\n---\n\n## 📖 概述与核心价值\n\n**MediaSync-Claw** 设计目的为提供个人媒体文件的远程共享与点对点流媒体服务。\n\n其核心价值在于：通过 WhatsApp 接入 OpenClaw AI 代理后，用户可以随时随地远程获取并检索本地电脑上的媒体文件列表。生成的媒体列表原生支持通过 **AIpollo Player** 进行高速 P2P 穿透播放。\n\n---\n\n## ⚙️ 使用前提\n\n* **OpenClaw**: 本地已成功部署并运行 OpenClaw 环境。\n* **安全软件加白**: 在系统安全软件（如 Windows Defender）中添加信任例外 `frpc.exe`。*我们保证官方提供的 `frpc.exe` 绝对安全无篡改。*\n\n---\n\n## 🚀 具体使用步骤\n\n1. **下载与安装**：下载并安装 MediaSync-Claw skill 至 OpenClaw 的 skills 目录下。\n2. **构建本地片源库**：在本 skill 的根目录中创建 `videos` 文件夹，并将需要远程访问的 MP4 视频文件放入其中。\n3. **配置 WhatsApp**：在 OpenClaw 中接入并完成 WhatsApp 通道配置。\n4. **运行 Skill**：在 OpenClaw 平台中启动并运行本 skill。\n5. **WhatsApp 远程交互**：在 WhatsApp 对话中发送自然语言指令（例如：当您想要查看、列出、搜索或播放本地视频库/播放列表时），触发本 skill 获取媒体列表。\n6. **调起播放**：点击媒体列表中返回的专属安全链接，即可在 AIpollo Player 中开始播放。\n\n---\n\n## 🔒 安全说明与风险披露\n\n### 风险 1：本地服务公网穿透访问\n本 skill 旨在提供便捷的远程媒体共享体验。为了实现跨局域网穿透，它通过 FRP（Fast Reverse Proxy）客户端（`frpc`）与远程中继服务器（`frps`）建立一条出站隧道，从而使您的本地媒体服务可通过 `*.yunfrp.net` 域名进行公网指令调度。\n\n### 风险 2：HTTP 明文传输与 P2P 播放架构\n本 skill 的核心视频流播放采用 **P2P 点对点传输**。HTTP 协议仅用于接收轻量控制指令，传输过程绝不涉及或上传任何用户的敏感个人隐私数据。\n\n### 风险 3：下载与拉起 `frpc.exe` 二进制组件\n为了支持跨网域 NAT 穿透与反向代理，本 skill 所需的 `frpc.exe` 均直接从官方 GitHub Releases 渠道获取，最大程度保证开源供应链的安全透明。\n\n---\n\n## 🛡️ 安全实践建议\n\n* **专用设备与隔离环境**：为了确保绝对安全，建议使用单独的闲置电脑或 NAS 作为媒体服务器，而非在主力工作设备上运行。若必须在主力机上运行，推荐使用虚拟机（VM）进行环境隔离。\n* **系统安全维护**：建议定期更新并升级您的操作系统补丁与 OpenClaw 运行环境，防范潜在安全漏洞。\n\n---\n\n## 💻 平台兼容性\n\n* **当前支持**：Windows (x64)\n* **后续规划**：Linux 与 macOS 平台支持正在积极适配中。\n\n*如需其他平台支持或在网络穿透中遇到问题，欢迎提交 GitHub Issue 或联系我们。感谢您的支持与信任！*\n\nFile v0.1.11:skill-card.md\n\n## Description:\n\nMediaSync-Claw lets an OpenClaw agent list, link, and stream local MP4 media through a local media server exposed for remote access.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[yu-libin](https://clawhub.ai/user/yu-libin)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nExternal OpenClaw users use this skill to browse and play MP4 files from a local videos folder through WhatsApp-driven agent requests. It is intended for users who deliberately want remote access to a local media library.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill can make a local media server reachable from the public internet through an unauthenticated tunnel.\n\nMitigation: Install only when remote media access is intended, run it on an isolated machine or VM, store only non-sensitive media in the videos folder, and add authentication, HTTPS, and rate limits before broader use.\n\nRisk: The skill downloads and runs a native FRP client binary.\n\nMitigation: Verify frpc manually, avoid broad antivirus exceptions, and keep dependencies and tunnel configuration under review.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/yu-libin/skills/mediasync-claw)\n- [MediaSync-Claw product documentation](https://poly-ai.chat/mediasync-claw)\n- [FRP v0.65.0 release used for client download](https://github.com/fatedier/frp/releases/tag/v0.65.0)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, configuration]\n\n**Output Format:** [JSON response containing human-facing text and media playback links]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Requires a local videos folder and a running OpenClaw media server; media files are linked rather than embedded in the agent response.]\n\n## Skill Version(s):\n\n0.1.11 (source: server release metadata; artifact frontmatter says 1.0.11)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nFile v0.1.11:requirements.txt\n\nflask>=3.1.3\r\nrequests>=2.32.4\r\njinja2>=3.1.6\r\naiortc\r\naiofiles\r\nflask-socketio\n\nArchive v0.1.10: 18 files, 28678 bytes\n\nFiles: .gitignore (10b), .vscode/settings.json (36b), CHANGELOG.md (314b), media_file_util.py (664b), media_frp_util.py (7593b), media_server_flask.py (19746b), README_DE.md (3191b), README_ES.md (3353b), README_JA.md (3784b), README_ZH.md (3240b), README.md (3670b), requirements.txt (79b), skill-card.md (2277b), SKILL.md (5638b), templates/medias.html (3637b), templates/player.html (12656b), uuid_config.py (895b), _meta.json (134b)\n\nFile v0.1.10:SKILL.md\n\n---\r\nname: MediaSync-Claw\r\nversion: 1.0.10\r\ndescription: This tool automatically downloads and executes the third-party 'frpc' binary from GitHub to establish an active outbound reverse tunnel. It exposes local file systems and port 8000 to the public internet via yunfrp.net subdomains. Additionally, it initiates outbound WebSocket/WebRTC signaling and connects to external STUN servers for peer-to-peer media streaming, enabling remote file access.\r\nauthor: OpenClaw User\r\ntype: workspace\r\nlanguage: python\r\nentrypoint: media_server_flask.py\r\nrequires:\r\n  bins:\r\n    - python3\r\n    - uv\r\n  python:\r\n    - \"flask>=3.1.3\"\r\n    - \"requests>=2.32.4\"\r\n    - \"jinja2>=3.1.6\"\r\n    - \"aiortc\"\r\n    - \"aiofiles\"\r\n    - \"flask-socketio\"\r\n\r\nactions:\r\n  - name: list_files\r\n    description: \"Call this tool when the user wants to view, list, play, or search for local videos or playlists (playlist/video library).\"\r\n    url: \"http://127.0.0.1:8000/api/list_files\"\r\n    method: \"POST\"\r\n    parameters:\r\n      type: object\r\n      properties:\r\n        query:\r\n          type: string\r\n          description: \"Keywords or filter conditions for the user query, optional.\"\r\n      required: []\r\n\r\npermissions:\r\n  - filesystem:read\r\n  - filesystem:write\r\n  - network:listen\r\n  - network:connect\r\n  - process:execute\r\n  - network:access:internal\r\n  - network:access:internet\r\n---\r\n\r\n# MediaSync-Claw\r\n\r\n## 🚀 Overview\r\n\r\n### Prerequisites:\r\n* **Environment**: Local OpenClaw environment successfully deployed.\r\n* **Antivirus**: Trust/add exception for `frpc.exe` in your security software if blocked.\r\n### Specific Steps:\r\n1. **Install**: Download and install the `MediaSync-Claw` skill via ClawHub.\r\n2. **Media Setup**: Create a `videos` directory inside this skill's folder and drop your MP4 files there.\r\n3.**Integration**: Link and configure your WhatsApp channel in OpenClaw.\r\n4. **Launch**: Start the `MediaSync-Claw` skill in OpenClaw.\r\n5. **Interact (LLM-Driven)**: Chat with the AI naturally in your channel. For example:\r\n   * *\"Show me my video list.\"*\r\n   * *\"Do I have any movie to watch?\"*\r\n   * *\"Play the video about cat.\"*\r\n6. **Play**: Click the generated link from the response to play your video.\r\n\r\n## 💡 LLM Agent Mode Active\r\nThis skill operates entirely at the **LLM Action/Tool execution level**. OpenClaw no longer intercepts requests via rigid keyword matching. Instead, the LLM intelligently understands user intents, translates fuzzy queries into structured API parameters, and hits your local Flask backend to fetch data.\r\n\r\n*Note: `media_server_flask.py` should return clean JSON data (e.g., file lists, file URLs). The LLM will automatically handle conversational rendering, typo correction, and personalized responses based on your data.*\r\n\r\n## 🔒 Security & Network Disclosure\r\n\r\n### ⚠️ Critical: FRP Tunnel Exposes Local Services to Public Internet\r\nThis skill **automatically** downloads and runs the **FRP (Fast Reverse Proxy) client (`frpc`)** upon startup. The `frpc` binary is fetched from GitHub Releases and establishes an outbound tunnel to a remote FRP server (`129.213.174.213:7000`), which in turn exposes your local media service (port 8000) to the **public internet** via a `*.yunfrp.net` subdomain.\r\n\r\n**This materially expands your attack surface.** Anyone who knows or discovers the public subdomain can attempt to access your media files and the Flask service running on your machine.\r\n\r\n### 1. Automatic Tunnel Behavior (No User Opt-in)\r\n* **Automatic on Startup**: The FRP tunnel starts automatically when `media_server_flask.py` runs. There is no prompt, no confirmation, and no environment-variable gate.\r\n* **Binary Download**: On first run, `frpc.exe` is downloaded silently from GitHub (`fatedier/frp` releases). Internet access is required.\r\n* **No Inbound Firewall Changes**: The tunnel is outbound-only; no inbound ports need to be opened on your firewall.\r\n\r\n### 2. Supply-Chain Risk: Downloaded Binary Execution\r\n* The skill downloads and executes a native binary (`frpc.exe`) from GitHub Releases. Compromise of the GitHub repository, the release artifact, or the network transport (MITM) could result in **arbitrary code execution** on your host with the same privileges as the Python process.\r\n* **Pinned SHA256 Verification**: The code includes hardcoded SHA256 checksums for both the zip archive and the extracted `frpc.exe` binary (version `0.65.0`). The download is rejected if either checksum does not match. This defends against transport tampering and corrupted downloads, but **does not protect against a compromise of the upstream GitHub repository or release**.\r\n* **Version-Locked**: The FRP version is pinned at `0.65.0`. Upgrading requires a code change and SHA256 re-verification. This prevents silent upgrades to potentially compromised newer versions.\r\n\r\n### 3. Authentication Status\r\n* **No Authentication Implemented**: The Flask server currently has **no HTTP Basic Auth, no token mechanism, and no access control**. All API routes and media endpoints are publicly accessible to anyone who reaches the server — whether via LAN or the FRP tunnel.\r\n* **Risk**: An unauthenticated third party who discovers the `*.yunfrp.net` subdomain can enumerate and download media files from your machine.\r\n\r\n### 4. Remote Server Trust\r\n* The FRP server at `129.213.174.213:7000` is a third-party relay. All traffic between the public internet and your local service passes through this server.\r\n* The FRP tunnel operates in HTTP mode (no TLS termination by FRP server).\r\n* You must trust that this FRP server operator will not inspect, log, or tamper with your traffic.\n\nFile v0.1.10:README.md\n\n<div align=\"center\">\n\n# MediaSync-Claw: Remote P2P Media Server & Streaming Skill for OpenClaw\n\n**[ 🌐 Visit Official Website & Full Documentation ](https://poly-ai.chat/mediasync-claw)**\n\n[English](README.md) | [简体中文](README_ZH.md) | [日本語](README_JA.md) | [Deutsch](README_DE.md) | [Español](README_ES.md)\n\n</div>\n\n---\n\n## 📖 Overview & Core Value\n\n**MediaSync-Claw** is a dedicated **OpenClaw Skill** and **Remote P2P Media Server** developed by [Poly AI](https://poly-ai.chat). \n\nIts core value is enabling users to access, index, and stream their local home PC media library **anytime, anywhere via WhatsApp** using the OpenClaw AI agent. The generated media list supports seamless playback with the **AIpollo Player** via high-speed P2P tunneling. \n\nFor advanced configurations, enterprise support, and the latest updates, please visit our **[Official Product Page](https://poly-ai.chat/mediasync-claw)**.\n\n---\n\n## ⚙️ Prerequisites\n\n* **OpenClaw**: Ensure OpenClaw is deployed and running in your local environment.\n* **Firewall / Antivirus Whitelist**: Add an exception (trust rule) for `frpc.exe` in your Windows Defender or antivirus software. *We ensure that `frpc.exe` is completely safe and unaltered.*\n\n---\n\n## 🚀 Step-by-Step Installation & Usage\n\n1. **Download & Install**: Clone or download this repository into your OpenClaw skills directory.\n2. **Setup Media Library**: Create a `videos` directory inside the skill folder and place the MP4 video files you wish to access remotely into it.\n3. **Configure WhatsApp**: Connect and configure your WhatsApp channel within OpenClaw.\n4. **Launch Skill**: Run the MediaSync-Claw skill in OpenClaw.\n5. **Remote Command via WhatsApp**: In your WhatsApp chat, send natural language requests (e.g., when you want to view, list, search, or play local videos/playlists from your video library) to trigger this skill and generate the media list.\n6. **One-Click Playback**: Click the generated link from the media list to start streaming on AIpollo Player.\n\n---\n\n## 🔒 Security Disclosures & Risk Management\n\n### Risk 1: Public Network Routing via FRP Reverse Proxy\nTo provide convenient remote media streaming across restricted local networks, this skill establishes an outbound tunnel using the FRP (Fast Reverse Proxy) client (`frpc`) to connect with an `frps` relay server. This enables public routing for your local media service via the `*.yunfrp.net` domain.\n\n### Risk 2: Plaintext HTTP Transmission & P2P Stream Architecture\nThe actual video streaming of this skill relies on **P2P direct connections**. HTTP is strictly used for transmitting lightweight control instructions and never carries sensitive personal user data.\n\n### Risk 3: Automated `frpc.exe` Binary Retrieval\nTo support cross-network NAT traversal and reverse proxying, the required `frpc.exe` binary is fetched directly from official GitHub releases to ensure maximum supply-chain integrity and security.\n\n---\n\n## 🛡️ Best Practice Recommendations\n\n* **Dedicated Server / Virtual Machine**: For optimal security, we strongly recommend running this media server skill on a standalone secondary device or within an isolated Virtual Machine (VM) rather than on your primary workstation.\n* **Routine Maintenance**: Keep your host operating system, OpenClaw environment, and security patches updated regularly.\n\n---\n\n## 💻 Platform Compatibility\n\n* **Current Support**: Windows (x64)\n* **Roadmap**: Linux / macOS support is under active development.\n\n*If you need support for other platforms or encounter network traversal issues, please open a GitHub Issue or reach out to us. Thank you for your support and trust!*\n\nFile v0.1.10:_meta.json\n\n{\n  \"ownerId\": \"kn723yj2g3pgy4vx13sg58hyk187z678\",\n  \"slug\": \"mediasync-claw\",\n  \"version\": \"0.1.10\",\n  \"publishedAt\": 1788505730468\n}\n\nFile v0.1.10:CHANGELOG.md\n\n# Changelog\r\n## - 2026-08-24\r\n- fix path issue\r\n## - 2026-08-20\r\n- fix security issue\r\n## - 2026-08-14\r\n- update the player URL generation logic.\r\n## - 2026-07-30\r\n- fix security issue.\r\n## - 2026-07-16\r\n- fix bug about file hash validation.\r\n## - 2026-05-28\r\n- Initial release with dynamic frpc environment setup.\n\nFile v0.1.10:README_DE.md\n\n<div align=\"center\">\n\n# MediaSync-Claw: Remote P2P-Medienserver & Streaming-Skill für OpenClaw\n\n[English](README.md) | [简体中文](README_ZH.md) | [日本語](README_JA.md) | [Deutsch](README_DE.md) | [Español](README_ES.md)\n\n</div>\n\n---\n\n## 📖 Übersicht & Kernfunktionalität\n\n**MediaSync-Claw** ist ein dedizierter **OpenClaw-Skill** und **P2P-Medienserver** für das persönliche Video- und Audiostreaming im Homelab- und Self-Hosted-Bereich.\n\nÜber die Anbindung von OpenClaw an WhatsApp können Sie jederzeit und von überall auf die Medienbibliothek Ihres lokalen Heim-PCs zugreifen. Die generierte Medienliste ermöglicht ein schnelles, verlustfreies P2P-Streaming über den **AIpollo Player**.\n\n---\n\n## ⚙️ Systemanforderungen\n\n* **OpenClaw**: OpenClaw ist lokal installiert und einsatzbereit.\n* **Firewall- / Antivirus-Freigabe**: Fügen Sie `frpc.exe` als Ausnahme in Windows Defender oder Ihrer Sicherheitssoftware hinzu. *Wir garantieren, dass `frpc.exe` absolut sicher und ungepatcht ist.*\n\n---\n\n## 🚀 Schritt-für-Schritt Installationsanleitung\n\n1. **Download & Installation**: Klonen oder laden Sie dieses Repository in das Skills-Verzeichnis von OpenClaw herunter.\n2. **Medienordner anlegen**: Erstellen Sie im Skill-Verzeichnis einen Ordner namens `videos` und hinterlegen Sie dort die MP4-Videodateien.\n3. **WhatsApp konfigurieren**: Richten Sie die WhatsApp-Schnittstelle in OpenClaw ein.\n4. **Skill ausführen**: Starten Sie den MediaSync-Claw-Skill in OpenClaw.\n5. **Fernsteuerung via WhatsApp**: Senden Sie einen Befehl über WhatsApp (z. B. wenn Sie Videos auflisten, suchen oder abspielen möchten), um die Medienliste abzurufen.\n6. **Wiedergabe starten**: Klicken Sie auf den generierten Link in der Medienliste, um den Stream im AIpollo Player zu starten.\n\n---\n\n## 🔒 Sicherheits- und Risikohinweise\n\n### Risiko 1: Öffentlicher Netzwerkzugriff via FRP-Reverse-Proxy\nUm Medien hinter NAT-Routern und Firewalls erreichbar zu machen, baut der FRP-Client (`frpc`) einen ausgehenden Tunnel zu einem Relay-Server (`frps`) auf. Dadurch wird der lokale Dienst über die Domain `*.yunfrp.net` erreichbar.\n\n### Risiko 2: HTTP-Klartextübertragung & P2P-Streaming\nDas eigentliche Videostreaming erfolgt über eine **direkte P2P-Verbindung**. Über HTTP werden ausschließlich Steuerbefehle übertragen; es werden keine sensiblen Benutzerdaten übertragen.\n\n### Risiko 3: Bezug der ausführbaren Datei `frpc.exe`\nUm die Integrität der Lieferkette zu gewährleisten, wird die Binärdatei `frpc.exe` direkt aus den offiziellen GitHub-Releases bezogen.\n\n---\n\n## 🛡️ Sicherheitsempfehlungen\n\n* **Dedizierte Hardware / Virtuelle Maschine**: Für maximale Sicherheit empfehlen wir, diesen Dienst auf einem separaten Server (z. B. Homelab/NAS) oder in einer isolierten virtuellen Maschine (VM) zu betreiben.\n* **Regelmäßige Updates**: Halten Sie Ihr Betriebssystem und Ihre OpenClaw-Umgebung stets auf dem neuesten Stand.\n\n---\n\n## 💻 Plattformkompatibilität\n\n* **Aktuell unterstützt**: Windows (x64)\n* **In Entwicklung**: Linux / macOS Support folgt in Kürze.\n\n*Bei Fragen oder Problemen öffnen Sie bitte ein GitHub-Issue. Vielen Dank für Ihr Vertrauen!*\n\nFile v0.1.10:README_ES.md\n\n<div align=\"center\">\n\n# MediaSync-Claw: Servidor Multimedia P2P Remoto y Skill de Streaming para OpenClaw\n\n[English](README.md) | [简体中文](README_ZH.md) | [日本語](README_JA.md) | [Deutsch](README_DE.md) | [Español](README_ES.md)\n\n</div>\n\n---\n\n## 📖 Descripción General y Valor Principal\n\n**MediaSync-Claw** es un **Skill de OpenClaw** y un **Servidor Multimedia P2P Remoto** diseñado para compartir y reproducir archivos de video y audio personales.\n\nSu objetivo principal es permitir a los usuarios acceder, indexar y transmitir su biblioteca multimedia local **en cualquier momento y lugar a través de WhatsApp** mediante el agente de IA OpenClaw. La lista multimedia generada es compatible con la reproducción de alta velocidad en **AIpollo Player** mediante conexiones P2P.\n\n---\n\n## ⚙️ Requisitos Previos\n\n* **OpenClaw**: Asegúrate de tener OpenClaw instalado y en ejecución localmente.\n* **Excepción de Firewall / Antivirus**: Agrega una regla de confianza para `frpc.exe` en Windows Defender o tu software de seguridad. *Garantizamos que `frpc.exe` es completamente seguro y original.*\n\n---\n\n## 🚀 Guía de Instalación y Uso\n\n1. **Descarga e Instalación**: Descarga o clona este repositorio dentro del directorio de skills de OpenClaw.\n2. **Configura la Carpeta de Videos**: Crea una carpeta llamada `videos` dentro del directorio del skill y coloca los archivos MP4 que deseas reproducir.\n3. **Conecta WhatsApp**: Configura e integra tu canal de WhatsApp en OpenClaw.\n4. **Ejecuta el Skill**: Inicia el skill MediaSync-Claw en OpenClaw.\n5. **Comandos Remotos por WhatsApp**: En tu chat de WhatsApp, escribe comandos en lenguaje natural (por ejemplo, para listar, buscar o reproducir videos de tu biblioteca local) para obtener la lista de medios.\n6. **Reproducción Inmediata**: Haz clic en el enlace generado para comenzar la transmisión en AIpollo Player.\n\n---\n\n## 🔒 Divulgación de Seguridad y Gestión de Riesgos\n\n### Riesgo 1: Enrutamiento Público mediante Proxy Inverso FRP\nPara facilitar la transmisión fuera de tu red local, este skill establece un túnel de salida mediante el cliente FRP (`frpc`) hacia un servidor de retransmisión (`frps`), permitiendo el acceso a través del dominio `*.yunfrp.net`.\n\n### Riesgo 2: Transmisión HTTP y Arquitectura P2P\nLa transmisión de video real se realiza mediante **conexiones directas P2P**. El protocolo HTTP se utiliza exclusivamente para recibir instrucciones ligeras de control y no transmite datos personales sensibles.\n\n### Riesgo 3: Descarga de Binarios `frpc.exe`\nPara garantizar la máxima seguridad en la cadena de suministro, el ejecutable `frpc.exe` se descarga directamente desde los Releases oficiales de GitHub.\n\n---\n\n## 🛡️ Recomendaciones de Seguridad\n\n* **Servidor Dedicado / Máquina Virtual**: Para una seguridad óptima, se recomienda ejecutar este servicio en un dispositivo secundario o dentro de una Máquina Virtual (VM) aislada.\n* **Mantenimiento Periódico**: Mantén actualizados tu sistema operativo y el entorno OpenClaw con los últimos parches de seguridad.\n\n---\n\n## 💻 Compatibilidad de Plataforma\n\n* **Soporte Actual**: Windows (x64)\n* **Próximamente**: Soporte para Linux y macOS en desarrollo.\n\n*Si necesitas soporte para otras plataformas o tienes dudas, abre un Issue en GitHub. ¡Gracias por tu confianza y apoyo!*\n\nFile v0.1.10:README_JA.md\n\n<div align=\"center\">\n\n# MediaSync-Claw: OpenClaw向けリモートP2Pメディアサーバー＆ストリーミングSkill\n\n[English](README.md) | [简体中文](README_ZH.md) | [日本語](README_JA.md) | [Deutsch](README_DE.md) | [Español](README_ES.md)\n\n</div>\n\n---\n\n## 📖 概要とコアバリュー\n\n**MediaSync-Claw** は、個人の動画・音声ファイルをリモートから安全にストリーミングするために設計された **OpenClaw Skill** および **P2Pメディアサーバー** です。\n\nOpenClaw を介して WhatsApp と連携することで、外出先からいつでも自宅PC内のメディアライブラリを検索・取得できます。生成されたメディアリストは、**AIpollo Player** による高速P2P通信でスムーズに再生可能です。\n\n---\n\n## ⚙️ 前提条件\n\n* **OpenClaw**: ローカル環境に OpenClaw が正常にデプロイされていること。\n* **セキュリティソフトの例外設定**: Windows Defender などのセキュリティソフトで `frpc.exe` を信頼（除外設定）に追加してください。*本プロジェクトの `frpc.exe` は改ざんのない安全なバイナリです。*\n\n---\n\n## 🚀 インストールと利用手順\n\n1. **ダウンロードと配置**: 本リポジトリをダウンロードし、OpenClaw の skills ディレクトリに配置します。\n2. **動画フォルダの作成**: 本スキルフォルダ内に `videos` ディレクトリを作成し、リモート再生したい MP4 ファイルを保存します。\n3. **WhatsApp の連携設定**: OpenClaw 上で WhatsApp 連携を設定します。\n4. **スキルの起動**: OpenClaw で MediaSync-Claw スキルを実行します。\n5. **WhatsApp からリモート操作**: WhatsApp チャット上で「動画一覧を見せて」「動画を再生」などのメッセージを送信すると、本スキルが呼び出され、メディアリストが返信されます。\n6. **ワンタップ再生**: リスト内のリンクをクリックし、AIpollo Player で動画をストリーミング再生します。\n\n---\n\n## 🔒 セキュリティとリスク開示\n\n### リスク 1: FRPリバースプロキシによるパブリックアクセス\nNAT越えおよびリモートアクセスを実現するため、FRP（Fast Reverse Proxy）クライアント（`frpc`）を使用してリレーサーバー（`frps`）へのアウトバウンドトンネルを確立します。これにより、ローカルのメディアサービスが `*.yunfrp.net` 経由でルーティングされます。\n\n### リスク 2: HTTP平文通信とP2Pストリーミング\n実際の動画データ転送には **P2P（ピアツーピア）直接通信** を使用します。HTTP 通信は軽量な制御コマンドの送受信のみに限定されており、ユーザーの機密情報が含まれることはありません。\n\n### リスク 3: `frpc.exe` バイナリの自動取得\n安全性を最大限確保するため、ネットワーク越えに必要な `frpc.exe` は公式の GitHub Releases から直接取得されます。\n\n---\n\n## 🛡️ 推奨セキュリティ対策\n\n* **専用端末・仮想マシンの利用**: 安全性を高めるため、メインの作業端末ではなく、専用のサブPCや仮想マシン（VM）上での実行を推奨します。\n* **定期的なアップデート**: OS および OpenClaw 環境を常に最新の状態に保つことをお勧めします。\n\n---\n\n## 💻 プラットフォーム対応状況\n\n* **現在対応**: Windows (x64)\n* **今後の予定**: Linux / macOS への対応を進めています。\n\n*ご質問や不具合がございましたら、GitHub Issue よりお気軽にお問い合わせください。*\n\nFile v0.1.10:README_ZH.md\n\n<div align=\"center\">\n\n# MediaSync-Claw: 基于 OpenClaw 的远程 P2P 媒体服务与流媒体 Skill\n\n[English](README.md) | [简体中文](README_ZH.md) | [日本語](README_JA.md) | [Deutsch](README_DE.md) | [Español](README_ES.md)\n\n</div>\n\n---\n\n## 📖 概述与核心价值\n\n**MediaSync-Claw** 设计目的为提供个人媒体文件的远程共享与点对点流媒体服务。\n\n其核心价值在于：通过 WhatsApp 接入 OpenClaw AI 代理后，用户可以随时随地远程获取并检索本地电脑上的媒体文件列表。生成的媒体列表原生支持通过 **AIpollo Player** 进行高速 P2P 穿透播放。\n\n---\n\n## ⚙️ 使用前提\n\n* **OpenClaw**: 本地已成功部署并运行 OpenClaw 环境。\n* **安全软件加白**: 在系统安全软件（如 Windows Defender）中添加信任例外 `frpc.exe`。*我们保证官方提供的 `frpc.exe` 绝对安全无篡改。*\n\n---\n\n## 🚀 具体使用步骤\n\n1. **下载与安装**：下载并安装 MediaSync-Claw skill 至 OpenClaw 的 skills 目录下。\n2. **构建本地片源库**：在本 skill 的根目录中创建 `videos` 文件夹，并将需要远程访问的 MP4 视频文件放入其中。\n3. **配置 WhatsApp**：在 OpenClaw 中接入并完成 WhatsApp 通道配置。\n4. **运行 Skill**：在 OpenClaw 平台中启动并运行本 skill。\n5. **WhatsApp 远程交互**：在 WhatsApp 对话中发送自然语言指令（例如：当您想要查看、列出、搜索或播放本地视频库/播放列表时），触发本 skill 获取媒体列表。\n6. **调起播放**：点击媒体列表中返回的专属安全链接，即可在 AIpollo Player 中开始播放。\n\n---\n\n## 🔒 安全说明与风险披露\n\n### 风险 1：本地服务公网穿透访问\n本 skill 旨在提供便捷的远程媒体共享体验。为了实现跨局域网穿透，它通过 FRP（Fast Reverse Proxy）客户端（`frpc`）与远程中继服务器（`frps`）建立一条出站隧道，从而使您的本地媒体服务可通过 `*.yunfrp.net` 域名进行公网指令调度。\n\n### 风险 2：HTTP 明文传输与 P2P 播放架构\n本 skill 的核心视频流播放采用 **P2P 点对点传输**。HTTP 协议仅用于接收轻量控制指令，传输过程绝不涉及或上传任何用户的敏感个人隐私数据。\n\n### 风险 3：下载与拉起 `frpc.exe` 二进制组件\n为了支持跨网域 NAT 穿透与反向代理，本 skill 所需的 `frpc.exe` 均直接从官方 GitHub Releases 渠道获取，最大程度保证开源供应链的安全透明。\n\n---\n\n## 🛡️ 安全实践建议\n\n* **专用设备与隔离环境**：为了确保绝对安全，建议使用单独的闲置电脑或 NAS 作为媒体服务器，而非在主力工作设备上运行。若必须在主力机上运行，推荐使用虚拟机（VM）进行环境隔离。\n* **系统安全维护**：建议定期更新并升级您的操作系统补丁与 OpenClaw 运行环境，防范潜在安全漏洞。\n\n---\n\n## 💻 平台兼容性\n\n* **当前支持**：Windows (x64)\n* **后续规划**：Linux 与 macOS 平台支持正在积极适配中。\n\n*如需其他平台支持或在网络穿透中遇到问题，欢迎提交 GitHub Issue 或联系我们。感谢您的支持与信任！*\n\nFile v0.1.10:skill-card.md\n\n## Description:\n\nMediaSync-Claw helps an OpenClaw agent list, search, and stream local MP4 files through WhatsApp using a local Flask media server, FRP tunneling, and WebRTC signaling.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[yu-libin](https://clawhub.ai/user/yu-libin)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nExternal users and OpenClaw developers use this skill to make a local personal media folder searchable from an OpenClaw-connected WhatsApp channel and return playback links for matching MP4 files.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill exposes a local media server to the public internet without authentication.\n\nMitigation: Install only when public remote media access is intended, run it in an isolated VM or spare machine, and avoid placing sensitive media in the videos folder.\n\nRisk: The skill downloads and executes a third-party FRP tunneling binary.\n\nMitigation: Do not whitelist or run frpc.exe unless you accept the supply-chain risk, and keep execution isolated from primary workstations and sensitive data.\n\nRisk: Anyone who discovers the yunfrp.net subdomain may try to list or fetch media.\n\nMitigation: Assume the generated public endpoint can be discovered and stop the skill or tunnel when remote streaming is not needed.\n\n## Reference(s):\n\n- [ClawHub Skill Page](https://clawhub.ai/yu-libin/skills/mediasync-claw)\n- [MediaSync-Claw README](artifact/README.md)\n- [MediaSync-Claw Product Page](https://poly-ai.chat/mediasync-claw)\n- [FRP v0.65.0 Release](https://github.com/fatedier/frp/releases/tag/v0.65.0)\n\n## Skill Output:\n\n**Output Type(s):** [Text, JSON]\n\n**Output Format:** [JSON responses containing human-readable media lists and playback links]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May include public playback URLs for discovered local MP4 files.]\n\n## Skill Version(s):\n\n0.1.10 (source: server release metadata; artifact frontmatter says 1.0.10)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nFile v0.1.10:.vscode/settings.json\n\n{\r\n    \"Codegeex.RepoIndex\": true\r\n}\n\nFile v0.1.10:requirements.txt\n\nflask>=3.1.3\r\nrequests>=2.32.4\r\njinja2>=3.1.6\r\naiortc\r\naiofiles\r\nflask-socketio\n\nArchive v0.1.9: 16 files, 25700 bytes\n\nFiles: CHANGELOG.md (314b), media_file_util.py (694b), media_frp_util.py (7356b), media_server_flask.py (10824b), README_DE.md (3191b), README_ES.md (3353b), README_JA.md (3784b), README_ZH.md (3240b), README.md (3670b), requirements.txt (69b), skill-card.md (2283b), SKILL.md (5619b), templates/medias.html (3637b), templates/player.html (9048b), uuid_config.py (981b), _meta.json (133b)\n\nFile v0.1.9:SKILL.md\n\n---\r\nname: MediaSync-Claw\r\nversion: 1.0.9\r\ndescription: This tool automatically downloads and executes the third-party 'frpc' binary from GitHub to establish an active outbound reverse tunnel. It exposes local file systems and port 8000 to the public internet via yunfrp.net subdomains. Additionally, it initiates outbound WebSocket/WebRTC signaling and connects to external STUN servers for peer-to-peer media streaming, enabling remote file access.\r\nauthor: OpenClaw User\r\ntype: workspace\r\nlanguage: python\r\nentrypoint: media_server_flask.py\r\nrequires:\r\n  bins:\r\n    - python3\r\n    - uv\r\n  python:\r\n    - \"flask>=3.1.3\"\r\n    - \"requests>=2.32.4\"\r\n    - \"jinja2>=3.1.6\"\r\n    - \"aiortc\"\r\n    - \"flask-socketio\"\r\n\r\nactions:\r\n  - name: list_files\r\n    description: \"Call this tool when the user wants to view, list, play, or search for local videos or playlists (playlist/video library).\"\r\n    url: \"http://127.0.0.1:8000/api/list_files\"\r\n    method: \"POST\"\r\n    parameters:\r\n      type: object\r\n      properties:\r\n        query:\r\n          type: string\r\n          description: \"Keywords or filter conditions for the user query, optional.\"\r\n      required: []\r\n\r\npermissions:\r\n  - filesystem:read\r\n  - filesystem:write\r\n  - network:listen\r\n  - network:connect\r\n  - process:execute\r\n  - network:access:internal\r\n  - network:access:internet\r\n---\r\n\r\n# MediaSync-Claw\r\n\r\n## 🚀 Overview\r\n\r\n### Prerequisites:\r\n* **Environment**: Local OpenClaw environment successfully deployed.\r\n* **Antivirus**: Trust/add exception for `frpc.exe` in your security software if blocked.\r\n### Specific Steps:\r\n1. **Install**: Download and install the `MediaSync-Claw` skill via ClawHub.\r\n2. **Media Setup**: Create a `videos` directory inside this skill's folder and drop your MP4 files there.\r\n3.**Integration**: Link and configure your WhatsApp channel in OpenClaw.\r\n4. **Launch**: Start the `MediaSync-Claw` skill in OpenClaw.\r\n5. **Interact (LLM-Driven)**: Chat with the AI naturally in your channel. For example:\r\n   * *\"Show me my video list.\"*\r\n   * *\"Do I have any movie to watch?\"*\r\n   * *\"Play the video about cat.\"*\r\n6. **Play**: Click the generated link from the response to play your video.\r\n\r\n## 💡 LLM Agent Mode Active\r\nThis skill operates entirely at the **LLM Action/Tool execution level**. OpenClaw no longer intercepts requests via rigid keyword matching. Instead, the LLM intelligently understands user intents, translates fuzzy queries into structured API parameters, and hits your local Flask backend to fetch data.\r\n\r\n*Note: `media_server_flask.py` should return clean JSON data (e.g., file lists, file URLs). The LLM will automatically handle conversational rendering, typo correction, and personalized responses based on your data.*\r\n\r\n## 🔒 Security & Network Disclosure\r\n\r\n### ⚠️ Critical: FRP Tunnel Exposes Local Services to Public Internet\r\nThis skill **automatically** downloads and runs the **FRP (Fast Reverse Proxy) client (`frpc`)** upon startup. The `frpc` binary is fetched from GitHub Releases and establishes an outbound tunnel to a remote FRP server (`129.213.174.213:7000`), which in turn exposes your local media service (port 8000) to the **public internet** via a `*.yunfrp.net` subdomain.\r\n\r\n**This materially expands your attack surface.** Anyone who knows or discovers the public subdomain can attempt to access your media files and the Flask service running on your machine.\r\n\r\n### 1. Automatic Tunnel Behavior (No User Opt-in)\r\n* **Automatic on Startup**: The FRP tunnel starts automatically when `media_server_flask.py` runs. There is no prompt, no confirmation, and no environment-variable gate.\r\n* **Binary Download**: On first run, `frpc.exe` is downloaded silently from GitHub (`fatedier/frp` releases). Internet access is required.\r\n* **No Inbound Firewall Changes**: The tunnel is outbound-only; no inbound ports need to be opened on your firewall.\r\n\r\n### 2. Supply-Chain Risk: Downloaded Binary Execution\r\n* The skill downloads and executes a native binary (`frpc.exe`) from GitHub Releases. Compromise of the GitHub repository, the release artifact, or the network transport (MITM) could result in **arbitrary code execution** on your host with the same privileges as the Python process.\r\n* **Pinned SHA256 Verification**: The code includes hardcoded SHA256 checksums for both the zip archive and the extracted `frpc.exe` binary (version `0.65.0`). The download is rejected if either checksum does not match. This defends against transport tampering and corrupted downloads, but **does not protect against a compromise of the upstream GitHub repository or release**.\r\n* **Version-Locked**: The FRP version is pinned at `0.65.0`. Upgrading requires a code change and SHA256 re-verification. This prevents silent upgrades to potentially compromised newer versions.\r\n\r\n### 3. Authentication Status\r\n* **No Authentication Implemented**: The Flask server currently has **no HTTP Basic Auth, no token mechanism, and no access control**. All API routes and media endpoints are publicly accessible to anyone who reaches the server — whether via LAN or the FRP tunnel.\r\n* **Risk**: An unauthenticated third party who discovers the `*.yunfrp.net` subdomain can enumerate and download media files from your machine.\r\n\r\n### 4. Remote Server Trust\r\n* The FRP server at `129.213.174.213:7000` is a third-party relay. All traffic between the public internet and your local service passes through this server.\r\n* The FRP tunnel operates in HTTP mode (no TLS termination by FRP server).\r\n* You must trust that this FRP server operator will not inspect, log, or tamper with your traffic.\n\nFile v0.1.9:README.md\n\n<div align=\"center\">\n\n# MediaSync-Claw: Remote P2P Media Server & Streaming Skill for OpenClaw\n\n**[ 🌐 Visit Official Website & Full Documentation ](https://poly-ai.chat/mediasync-claw)**\n\n[English](README.md) | [简体中文](README_ZH.md) | [日本語](README_JA.md) | [Deutsch](README_DE.md) | [Español](README_ES.md)\n\n</div>\n\n---\n\n## 📖 Overview & Core Value\n\n**MediaSync-Claw** is a dedicated **OpenClaw Skill** and **Remote P2P Media Server** developed by [Poly AI](https://poly-ai.chat). \n\nIts core value is enabling users to access, index, and stream their local home PC media library **anytime, anywhere via WhatsApp** using the OpenClaw AI agent. The generated media list supports seamless playback with the **AIpollo Player** via high-speed P2P tunneling. \n\nFor advanced configurations, enterprise support, and the latest updates, please visit our **[Official Product Page](https://poly-ai.chat/mediasync-claw)**.\n\n---\n\n## ⚙️ Prerequisites\n\n* **OpenClaw**: Ensure OpenClaw is deployed and running in your local environment.\n* **Firewall / Antivirus Whitelist**: Add an exception (trust rule) for `frpc.exe` in your Windows Defender or antivirus software. *We ensure that `frpc.exe` is completely safe and unaltered.*\n\n---\n\n## 🚀 Step-by-Step Installation & Usage\n\n1. **Download & Install**: Clone or download this repository into your OpenClaw skills directory.\n2. **Setup Media Library**: Create a `videos` directory inside the skill folder and place the MP4 video files you wish to access remotely into it.\n3. **Configure WhatsApp**: Connect and configure your WhatsApp channel within OpenClaw.\n4. **Launch Skill**: Run the MediaSync-Claw skill in OpenClaw.\n5. **Remote Command via WhatsApp**: In your WhatsApp chat, send natural language requests (e.g., when you want to view, list, search, or play local videos/playlists from your video library) to trigger this skill and generate the media list.\n6. **One-Click Playback**: Click the generated link from the media list to start streaming on AIpollo Player.\n\n---\n\n## 🔒 Security Disclosures & Risk Management\n\n### Risk 1: Public Network Routing via FRP Reverse Proxy\nTo provide convenient remote media streaming across restricted local networks, this skill establishes an outbound tunnel using the FRP (Fast Reverse Proxy) client (`frpc`) to connect with an `frps` relay server. This enables public routing for your local media service via the `*.yunfrp.net` domain.\n\n### Risk 2: Plaintext HTTP Transmission & P2P Stream Architecture\nThe actual video streaming of this skill relies on **P2P direct connections**. HTTP is strictly used for transmitting lightweight control instructions and never carries sensitive personal user data.\n\n### Risk 3: Automated `frpc.exe` Binary Retrieval\nTo support cross-network NAT traversal and reverse proxying, the required `frpc.exe` binary is fetched directly from official GitHub releases to ensure maximum supply-chain integrity and security.\n\n---\n\n## 🛡️ Best Practice Recommendations\n\n* **Dedicated Server / Virtual Machine**: For optimal security, we strongly recommend running this media server skill on a standalone secondary device or within an isolated Virtual Machine (VM) rather than on your primary workstation.\n* **Routine Maintenance**: Keep your host operating system, OpenClaw environment, and security patches updated regularly.\n\n---\n\n## 💻 Platform Compatibility\n\n* **Current Support**: Windows (x64)\n* **Roadmap**: Linux / macOS support is under active development.\n\n*If you need support for other platforms or encounter network traversal issues, please open a GitHub Issue or reach out to us. Thank you for your support and trust!*\n\nFile v0.1.9:_meta.json\n\n{\n  \"ownerId\": \"kn723yj2g3pgy4vx13sg58hyk187z678\",\n  \"slug\": \"mediasync-claw\",\n  \"version\": \"0.1.9\",\n  \"publishedAt\": 1787540322747\n}\n\nFile v0.1.9:CHANGELOG.md\n\n# Changelog\r\n## - 2026-08-24\r\n- fix path issue\r\n## - 2026-08-20\r\n- fix security issue\r\n## - 2026-08-14\r\n- update the player URL generation logic.\r\n## - 2026-07-30\r\n- fix security issue.\r\n## - 2026-07-16\r\n- fix bug about file hash validation.\r\n## - 2026-05-28\r\n- Initial release with dynamic frpc environment setup.\n\nFile v0.1.9:README_DE.md\n\n<div align=\"center\">\n\n# MediaSync-Claw: Remote P2P-Medienserver & Streaming-Skill für OpenClaw\n\n[English](README.md) | [简体中文](README_ZH.md) | [日本語](README_JA.md) | [Deutsch](README_DE.md) | [Español](README_ES.md)\n\n</div>\n\n---\n\n## 📖 Übersicht & Kernfunktionalität\n\n**MediaSync-Claw** ist ein dedizierter **OpenClaw-Skill** und **P2P-Medienserver** für das persönliche Video- und Audiostreaming im Homelab- und Self-Hosted-Bereich.\n\nÜber die Anbindung von OpenClaw an WhatsApp können Sie jederzeit und von überall auf die Medienbibliothek Ihres lokalen Heim-PCs zugreifen. Die generierte Medienliste ermöglicht ein schnelles, verlustfreies P2P-Streaming über den **AIpollo Player**.\n\n---\n\n## ⚙️ Systemanforderungen\n\n* **OpenClaw**: OpenClaw ist lokal installiert und einsatzbereit.\n* **Firewall- / Antivirus-Freigabe**: Fügen Sie `frpc.exe` als Ausnahme in Windows Defender oder Ihrer Sicherheitssoftware hinzu. *Wir garantieren, dass `frpc.exe` absolut sicher und ungepatcht ist.*\n\n---\n\n## 🚀 Schritt-für-Schritt Installationsanleitung\n\n1. **Download & Installation**: Klonen oder laden Sie dieses Repository in das Skills-Verzeichnis von OpenClaw herunter.\n2. **Medienordner anlegen**: Erstellen Sie im Skill-Verzeichnis einen Ordner namens `videos` und hinterlegen Sie dort die MP4-Videodateien.\n3. **WhatsApp konfigurieren**: Richten Sie die WhatsApp-Schnittstelle in OpenClaw ein.\n4. **Skill ausführen**: Starten Sie den MediaSync-Claw-Skill in OpenClaw.\n5. **Fernsteuerung via WhatsApp**: Senden Sie einen Befehl über WhatsApp (z. B. wenn Sie Videos auflisten, suchen oder abspielen möchten), um die Medienliste abzurufen.\n6. **Wiedergabe starten**: Klicken Sie auf den generierten Link in der Medienliste, um den Stream im AIpollo Player zu starten.\n\n---\n\n## 🔒 Sicherheits- und Risikohinweise\n\n### Risiko 1: Öffentlicher Netzwerkzugriff via FRP-Reverse-Proxy\nUm Medien hinter NAT-Routern und Firewalls erreichbar zu machen, baut der FRP-Client (`frpc`) einen ausgehenden Tunnel zu einem Relay-Server (`frps`) auf. Dadurch wird der lokale Dienst über die Domain `*.yunfrp.net` erreichbar.\n\n### Risiko 2: HTTP-Klartextübertragung & P2P-Streaming\nDas eigentliche Videostreaming erfolgt über eine **direkte P2P-Verbindung**. Über HTTP werden ausschließlich Steuerbefehle übertragen; es werden keine sensiblen Benutzerdaten übertragen.\n\n### Risiko 3: Bezug der ausführbaren Datei `frpc.exe`\nUm die Integrität der Lieferkette zu gewährleisten, wird die Binärdatei `frpc.exe` direkt aus den offiziellen GitHub-Releases bezogen.\n\n---\n\n## 🛡️ Sicherheitsempfehlungen\n\n* **Dedizierte Hardware / Virtuelle Maschine**: Für maximale Sicherheit empfehlen wir, diesen Dienst auf einem separaten Server (z. B. Homelab/NAS) oder in einer isolierten virtuellen Maschine (VM) zu betreiben.\n* **Regelmäßige Updates**: Halten Sie Ihr Betriebssystem und Ihre OpenClaw-Umgebung stets auf dem neuesten Stand.\n\n---\n\n## 💻 Plattformkompatibilität\n\n* **Aktuell unterstützt**: Windows (x64)\n* **In Entwicklung**: Linux / macOS Support folgt in Kürze.\n\n*Bei Fragen oder Problemen öffnen Sie bitte ein GitHub-Issue. Vielen Dank für Ihr Vertrauen!*\n\nFile v0.1.9:README_ES.md\n\n<div align=\"center\">\n\n# MediaSync-Claw: Servidor Multimedia P2P Remoto y Skill de Streaming para OpenClaw\n\n[English](README.md) | [简体中文](README_ZH.md) | [日本語](README_JA.md) | [Deutsch](README_DE.md) | [Español](README_ES.md)\n\n</div>\n\n---\n\n## 📖 Descripción General y Valor Principal\n\n**MediaSync-Claw** es un **Skill de OpenClaw** y un **Servidor Multimedia P2P Remoto** diseñado para compartir y reproducir archivos de video y audio personales.\n\nSu objetivo principal es permitir a los usuarios acceder, indexar y transmitir su biblioteca multimedia local **en cualquier momento y lugar a través de WhatsApp** mediante el agente de IA OpenClaw. La lista multimedia generada es compatible con la reproducción de alta velocidad en **AIpollo Player** mediante conexiones P2P.\n\n---\n\n## ⚙️ Requisitos Previos\n\n* **OpenClaw**: Asegúrate de tener OpenClaw instalado y en ejecución localmente.\n* **Excepción de Firewall / Antivirus**: Agrega una regla de confianza para `frpc.exe` en Windows Defender o tu software de seguridad. *Garantizamos que `frpc.exe` es completamente seguro y original.*\n\n---\n\n## 🚀 Guía de Instalación y Uso\n\n1. **Descarga e Instalación**: Descarga o clona este repositorio dentro del directorio de skills de OpenClaw.\n2. **Configura la Carpeta de Videos**: Crea una carpeta llamada `videos` dentro del directorio del skill y coloca los archivos MP4 que deseas reproducir.\n3. **Conecta WhatsApp**: Configura e integra tu canal de WhatsApp en OpenClaw.\n4. **Ejecuta el Skill**: Inicia el skill MediaSync-Claw en OpenClaw.\n5. **Comandos Remotos por WhatsApp**: En tu chat de WhatsApp, escribe comandos en lenguaje natural (por ejemplo, para listar, buscar o reproducir videos de tu biblioteca local) para obtener la lista de medios.\n6. **Reproducción Inmediata**: Haz clic en el enlace generado para comenzar la transmisión en AIpollo Player.\n\n---\n\n## 🔒 Divulgación de Seguridad y Gestión de Riesgos\n\n### Riesgo 1: Enrutamiento Público mediante Proxy Inverso FRP\nPara facilitar la transmisión fuera de tu red local, este skill establece un túnel de salida mediante el cliente FRP (`frpc`) hacia un servidor de retransmisión (`frps`), permitiendo el acceso a través del dominio `*.yunfrp.net`.\n\n### Riesgo 2: Transmisión HTTP y Arquitectura P2P\nLa transmisión de video real se realiza mediante **conexiones directas P2P**. El protocolo HTTP se utiliza exclusivamente para recibir instrucciones ligeras de control y no transmite datos personales sensibles.\n\n### Riesgo 3: Descarga de Binarios `frpc.exe`\nPara garantizar la máxima seguridad en la cadena de suministro, el ejecutable `frpc.exe` se descarga directamente desde los Releases oficiales de GitHub.\n\n---\n\n## 🛡️ Recomendaciones de Seguridad\n\n* **Servidor Dedicado / Máquina Virtual**: Para una seguridad óptima, se recomienda ejecutar este servicio en un dispositivo secundario o dentro de una Máquina Virtual (VM) aislada.\n* **Mantenimiento Periódico**: Mantén actualizados tu sistema operativo y el entorno OpenClaw con los últimos parches de seguridad.\n\n---\n\n## 💻 Compatibilidad de Plataforma\n\n* **Soporte Actual**: Windows (x64)\n* **Próximamente**: Soporte para Linux y macOS en desarrollo.\n\n*Si necesitas soporte para otras plataformas o tienes dudas, abre un Issue en GitHub. ¡Gracias por tu confianza y apoyo!*\n\nFile v0.1.9:README_JA.md\n\n<div align=\"center\">\n\n# MediaSync-Claw: OpenClaw向けリモートP2Pメディアサーバー＆ストリーミングSkill\n\n[English](README.md) | [简体中文](README_ZH.md) | [日本語](README_JA.md) | [Deutsch](README_DE.md) | [Español](README_ES.md)\n\n</div>\n\n---\n\n## 📖 概要とコアバリュー\n\n**MediaSync-Claw** は、個人の動画・音声ファイルをリモートから安全にストリーミングするために設計された **OpenClaw Skill** および **P2Pメディアサーバー** です。\n\nOpenClaw を介して WhatsApp と連携することで、外出先からいつでも自宅PC内のメディアライブラリを検索・取得できます。生成されたメディアリストは、**AIpollo Player** による高速P2P通信でスムーズに再生可能です。\n\n---\n\n## ⚙️ 前提条件\n\n* **OpenClaw**: ローカル環境に OpenClaw が正常にデプロイされていること。\n* **セキュリティソフトの例外設定**: Windows Defender などのセキュリティソフトで `frpc.exe` を信頼（除外設定）に追加してください。*本プロジェクトの `frpc.exe` は改ざんのない安全なバイナリです。*\n\n---\n\n## 🚀 インストールと利用手順\n\n1. **ダウンロードと配置**: 本リポジトリをダウンロードし、OpenClaw の skills ディレクトリに配置します。\n2. **動画フォルダの作成**: 本スキルフォルダ内に `videos` ディレクトリを作成し、リモート再生したい MP4 ファイルを保存します。\n3. **WhatsApp の連携設定**: OpenClaw 上で WhatsApp 連携を設定します。\n4. **スキルの起動**: OpenClaw で MediaSync-Claw スキルを実行します。\n5. **WhatsApp からリモート操作**: WhatsApp チャット上で「動画一覧を見せて」「動画を再生」などのメッセージを送信すると、本スキルが呼び出され、メディアリストが返信されます。\n6. **ワンタップ再生**: リスト内のリンクをクリックし、AIpollo Player で動画をストリーミング再生します。\n\n---\n\n## 🔒 セキュリティとリスク開示\n\n### リスク 1: FRPリバースプロキシによるパブリックアクセス\nNAT越えおよびリモートアクセスを実現するため、FRP（Fast Reverse Proxy）クライアント（`frpc`）を使用してリレーサーバー（`frps`）へのアウトバウンドトンネルを確立します。これにより、ローカルのメディアサービスが `*.yunfrp.net` 経由でルーティングされます。\n\n### リスク 2: HTTP平文通信とP2Pストリーミング\n実際の動画データ転送には **P2P（ピアツーピア）直接通信** を使用します。HTTP 通信は軽量な制御コマンドの送受信のみに限定されており、ユーザーの機密情報が含まれることはありません。\n\n### リスク 3: `frpc.exe` バイナリの自動取得\n安全性を最大限確保するため、ネットワーク越えに必要な `frpc.exe` は公式の GitHub Releases から直接取得されます。\n\n---\n\n## 🛡️ 推奨セキュリティ対策\n\n* **専用端末・仮想マシンの利用**: 安全性を高めるため、メインの作業端末ではなく、専用のサブPCや仮想マシン（VM）上での実行を推奨します。\n* **定期的なアップデート**: OS および OpenClaw 環境を常に最新の状態に保つことをお勧めします。\n\n---\n\n## 💻 プラットフォーム対応状況\n\n* **現在対応**: Windows (x64)\n* **今後の予定**: Linux / macOS への対応を進めています。\n\n*ご質問や不具合がございましたら、GitHub Issue よりお気軽にお問い合わせください。*\n\nFile v0.1.9:README_ZH.md\n\n<div align=\"center\">\n\n# MediaSync-Claw: 基于 OpenClaw 的远程 P2P 媒体服务与流媒体 Skill\n\n[English](README.md) | [简体中文](README_ZH.md) | [日本語](README_JA.md) | [Deutsch](README_DE.md) | [Español](README_ES.md)\n\n</div>\n\n---\n\n## 📖 概述与核心价值\n\n**MediaSync-Claw** 设计目的为提供个人媒体文件的远程共享与点对点流媒体服务。\n\n其核心价值在于：通过 WhatsApp 接入 OpenClaw AI 代理后，用户可以随时随地远程获取并检索本地电脑上的媒体文件列表。生成的媒体列表原生支持通过 **AIpollo Player** 进行高速 P2P 穿透播放。\n\n---\n\n## ⚙️ 使用前提\n\n* **OpenClaw**: 本地已成功部署并运行 OpenClaw 环境。\n* **安全软件加白**: 在系统安全软件（如 Windows Defender）中添加信任例外 `frpc.exe`。*我们保证官方提供的 `frpc.exe` 绝对安全无篡改。*\n\n---\n\n## 🚀 具体使用步骤\n\n1. **下载与安装**：下载并安装 MediaSync-Claw skill 至 OpenClaw 的 skills 目录下。\n2. **构建本地片源库**：在本 skill 的根目录中创建 `videos` 文件夹，并将需要远程访问的 MP4 视频文件放入其中。\n3. **配置 WhatsApp**：在 OpenClaw 中接入并完成 WhatsApp 通道配置。\n4. **运行 Skill**：在 OpenClaw 平台中启动并运行本 skill。\n5. **WhatsApp 远程交互**：在 WhatsApp 对话中发送自然语言指令（例如：当您想要查看、列出、搜索或播放本地视频库/播放列表时），触发本 skill 获取媒体列表。\n6. **调起播放**：点击媒体列表中返回的专属安全链接，即可在 AIpollo Player 中开始播放。\n\n---\n\n## 🔒 安全说明与风险披露\n\n### 风险 1：本地服务公网穿透访问\n本 skill 旨在提供便捷的远程媒体共享体验。为了实现跨局域网穿透，它通过 FRP（Fast Reverse Proxy）客户端（`frpc`）与远程中继服务器（`frps`）建立一条出站隧道，从而使您的本地媒体服务可通过 `*.yunfrp.net` 域名进行公网指令调度。\n\n### 风险 2：HTTP 明文传输与 P2P 播放架构\n本 skill 的核心视频流播放采用 **P2P 点对点传输**。HTTP 协议仅用于接收轻量控制指令，传输过程绝不涉及或上传任何用户的敏感个人隐私数据。\n\n### 风险 3：下载与拉起 `frpc.exe` 二进制组件\n为了支持跨网域 NAT 穿透与反向代理，本 skill 所需的 `frpc.exe` 均直接从官方 GitHub Releases 渠道获取，最大程度保证开源供应链的安全透明。\n\n---\n\n## 🛡️ 安全实践建议\n\n* **专用设备与隔离环境**：为了确保绝对安全，建议使用单独的闲置电脑或 NAS 作为媒体服务器，而非在主力工作设备上运行。若必须在主力机上运行，推荐使用虚拟机（VM）进行环境隔离。\n* **系统安全维护**：建议定期更新并升级您的操作系统补丁与 OpenClaw 运行环境，防范潜在安全漏洞。\n\n---\n\n## 💻 平台兼容性\n\n* **当前支持**：Windows (x64)\n* **后续规划**：Linux 与 macOS 平台支持正在积极适配中。\n\n*如需其他平台支持或在网络穿透中遇到问题，欢迎提交 GitHub Issue 或联系我们。感谢您的支持与信任！*\n\nFile v0.1.9:skill-card.md\n\n## Description:\n\nMediaSync-Claw lets an OpenClaw agent list, search, and return playback links for local media files through a Flask media service that can be exposed remotely through an FRP tunnel.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[yu-libin](https://clawhub.ai/user/yu-libin)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nExternal OpenClaw users use this skill to browse and play a local home media library from WhatsApp through AI-generated media links. It is intended for personal remote streaming on a Windows x64 host.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill can make a local media service reachable from the public internet without built-in authentication.\n\nMitigation: Install only when public remote access is intended, review or add authentication before exposure, and do not rely on the public subdomain for privacy or access control.\n\nRisk: Public access to the media service may expose local media files if the subdomain is discovered.\n\nMitigation: Run the skill on an isolated VM or dedicated host and place only non-sensitive MP4 files in the videos directory.\n\nRisk: The release has a suspicious security verdict in the authoritative scan evidence.\n\nMitigation: Review the scan summary and guidance carefully before installation, especially when running on a primary workstation.\n\n## Reference(s):\n\n- [ClawHub skill listing](https://clawhub.ai/yu-libin/skills/mediasync-claw)\n- [MediaSync-Claw product documentation](https://poly-ai.chat/mediasync-claw)\n- [FRP v0.65.0 release](https://github.com/fatedier/frp/releases/tag/v0.65.0)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, API calls, guidance]\n\n**Output Format:** [JSON responses containing text with media lists and playback links]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Produces links for media files discovered in the local videos directory.]\n\n## Skill Version(s):\n\n0.1.9 (source: server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nFile v0.1.9:requirements.txt\n\nflask>=3.1.3\r\nrequests>=2.32.4\r\njinja2>=3.1.6\r\naiortc\r\nflask-socketio\n\nArchive v0.1.8: 12 files, 17263 bytes\n\nFiles: CHANGELOG.md (279b), media_file_util.py (694b), media_frp_util.py (7356b), media_server_flask.py (10834b), readme.md (1957b), requirements.txt (69b), skill-card.md (2368b), SKILL.md (5619b), templates/medias.html (3637b), templates/player.html (9048b), uuid_config.py (981b), _meta.json (133b)\n\nFile v0.1.8:SKILL.md\n\n---\r\nname: MediaSync-Claw\r\nversion: 1.0.8\r\ndescription: This tool automatically downloads and executes the third-party 'frpc' binary from GitHub to establish an active outbound reverse tunnel. It exposes local file systems and port 8000 to the public internet via yunfrp.net subdomains. Additionally, it initiates outbound WebSocket/WebRTC signaling and connects to external STUN servers for peer-to-peer media streaming, enabling remote file access.\r\nauthor: OpenClaw User\r\ntype: workspace\r\nlanguage: python\r\nentrypoint: media_server_flask.py\r\nrequires:\r\n  bins:\r\n    - python3\r\n    - uv\r\n  python:\r\n    - \"flask>=3.1.3\"\r\n    - \"requests>=2.32.4\"\r\n    - \"jinja2>=3.1.6\"\r\n    - \"aiortc\"\r\n    - \"flask-socketio\"\r\n\r\nactions:\r\n  - name: list_files\r\n    description: \"Call this tool when the user wants to view, list, play, or search for local videos or playlists (playlist/video library).\"\r\n    url: \"http://127.0.0.1:8000/api/list_files\"\r\n    method: \"POST\"\r\n    parameters:\r\n      type: object\r\n      properties:\r\n        query:\r\n          type: string\r\n          description: \"Keywords or filter conditions for the user query, optional.\"\r\n      required: []\r\n\r\npermissions:\r\n  - filesystem:read\r\n  - filesystem:write\r\n  - network:listen\r\n  - network:connect\r\n  - process:execute\r\n  - network:access:internal\r\n  - network:access:internet\r\n---\r\n\r\n# MediaSync-Claw\r\n\r\n## 🚀 Overview\r\n\r\n### Prerequisites:\r\n* **Environment**: Local OpenClaw environment successfully deployed.\r\n* **Antivirus**: Trust/add exception for `frpc.exe` in your security software if blocked.\r\n### Specific Steps:\r\n1. **Install**: Download and install the `MediaSync-Claw` skill via ClawHub.\r\n2. **Media Setup**: Create a `videos` directory inside this skill's folder and drop your MP4 files there.\r\n3.**Integration**: Link and configure your WhatsApp channel in OpenClaw.\r\n4. **Launch**: Start the `MediaSync-Claw` skill in OpenClaw.\r\n5. **Interact (LLM-Driven)**: Chat with the AI naturally in your channel. For example:\r\n   * *\"Show me my video list.\"*\r\n   * *\"Do I have any movie to watch?\"*\r\n   * *\"Play the video about cat.\"*\r\n6. **Play**: Click the generated link from the response to play your video.\r\n\r\n## 💡 LLM Agent Mode Active\r\nThis skill operates entirely at the **LLM Action/Tool execution level**. OpenClaw no longer intercepts requests via rigid keyword matching. Instead, the LLM intelligently understands user intents, translates fuzzy queries into structured API parameters, and hits your local Flask backend to fetch data.\r\n\r\n*Note: `media_server_flask.py` should return clean JSON data (e.g., file lists, file URLs). The LLM will automatically handle conversational rendering, typo correction, and personalized responses based on your data.*\r\n\r\n## 🔒 Security & Network Disclosure\r\n\r\n### ⚠️ Critical: FRP Tunnel Exposes Local Services to Public Internet\r\nThis skill **automatically** downloads and runs the **FRP (Fast Reverse Proxy) client (`frpc`)** upon startup. The `frpc` binary is fetched from GitHub Releases and establishes an outbound tunnel to a remote FRP server (`129.213.174.213:7000`), which in turn exposes your local media service (port 8000) to the **public internet** via a `*.yunfrp.net` subdomain.\r\n\r\n**This materially expands your attack surface.** Anyone who knows or discovers the public subdomain can attempt to access your media files and the Flask service running on your machine.\r\n\r\n### 1. Automatic Tunnel Behavior (No User Opt-in)\r\n* **Automatic on Startup**: The FRP tunnel starts automatically when `media_server_flask.py` runs. There is no prompt, no confirmation, and no environment-variable gate.\r\n* **Binary Download**: On first run, `frpc.exe` is downloaded silently from GitHub (`fatedier/frp` releases). Internet access is required.\r\n* **No Inbound Firewall Changes**: The tunnel is outbound-only; no inbound ports need to be opened on your firewall.\r\n\r\n### 2. Supply-Chain Risk: Downloaded Binary Execution\r\n* The skill downloads and executes a native binary (`frpc.exe`) from GitHub Releases. Compromise of the GitHub repository, the release artifact, or the network transport (MITM) could result in **arbitrary code execution** on your host with the same privileges as the Python process.\r\n* **Pinned SHA256 Verification**: The code includes hardcoded SHA256 checksums for both the zip archive and the extracted `frpc.exe` binary (version `0.65.0`). The download is rejected if either checksum does not match. This defends against transport tampering and corrupted downloads, but **does not protect against a compromise of the upstream GitHub repository or release**.\r\n* **Version-Locked**: The FRP version is pinned at `0.65.0`. Upgrading requires a code change and SHA256 re-verification. This prevents silent upgrades to potentially compromised newer versions.\r\n\r\n### 3. Authentication Status\r\n* **No Authentication Implemented**: The Flask server currently has **no HTTP Basic Auth, no token mechanism, and no access control**. All API routes and media endpoints are publicly accessible to anyone who reaches the server — whether via LAN or the FRP tunnel.\r\n* **Risk**: An unauthenticated third party who discovers the `*.yunfrp.net` subdomain can enumerate and download media files from your machine.\r\n\r\n### 4. Remote Server Trust\r\n* The FRP server at `129.213.174.213:7000` is a third-party relay. All traffic between the public internet and your local service passes through this server.\r\n* The FRP tunnel operates in HTTP mode (no TLS termination by FRP server).\r\n* You must trust that this FRP server operator will not inspect, log, or tamper with your traffic.\n\nFile v0.1.8:readme.md\n\nskill使用说明：\r\n\r\nMediaSync-Claw 设计目的既提供个人媒体文件的远程共享服务。\r\n核心价值是通过WhatsApp接入openclaw后随时随地获取远程的媒体文件列表，媒体列表支持AIpollo player播放。\r\n\r\n使用前提：\r\n* 本地已经部署openclaw\r\n* 在系统安全软件中添加例外（信任）frpc.exe, 我们保证frpc.exe是安全的\r\n\r\n具体步骤：\r\n1. 下载并安装MediaSync-Claw skill\r\n2. 在本skill的目录中创建videos目录并把需要远程访问的MP4文件放入其中\r\n3. 在openclaw中接入whatsapp并配置\r\n4. 在openclaw中运行本skill\r\n5. 在whatsapp中发送当用户想要查看、列出、播放或搜索本地视频或播放列表（播放列表/视频库）时，调用本skill获取媒体列表。\r\n6. 选中媒体列表中的连接播放\r\n\r\n\r\n风险1：本地服务公网访问\r\n本skill旨在提供一个便捷的远程媒体共享服务，为了实现这一目标，它通过 FRP（Fast Reverse Proxy）客户端（frpc）与远程 FRP 服务器（frps）建立一个出站隧道，从而将你的本地媒体服务可以公网通过*.yunfrp.net域名来访问。\r\n\r\n风险2：HTTP明文传输\r\n本skill的播放功能是p2p播放，HTTP仅用于接受指令，不涉及用户的敏感信息。\r\n\r\n风险3：下载/拉起frpc.exe\r\n本skill为了支持跨网域访问需要配置反向代理等服务，为了最大限度保证安全frpc.exe是直接从git上获取。\r\n\r\n为了确保安全，我们建议使用单独的设备来作为媒体服务器，而不是在你的主设备上运行。这样可以避免潜在的安全风险。如果必须在主设备上运行，建议使用虚拟机来隔离媒体服务器和主设备。同时，建议定期更新和升级你的系统和软件，以确保安全。\r\n\r\n目前仅支持windows平台，后续会逐步支持其他平台。如果需要其他平台的支持，请随时联系我们。感谢您的支持和信任！\n\nFile v0.1.8:_meta.json\n\n{\n  \"ownerId\": \"kn723yj2g3pgy4vx13sg58hyk187z678\",\n  \"slug\": \"mediasync-claw\",\n  \"version\": \"0.1.8\",\n  \"publishedAt\": 1787221894394\n}\n\nFile v0.1.8:CHANGELOG.md\n\n# Changelog\r\n## - 2026-08-20\r\n- fix security issue\r\n## - 2026-08-14\r\n- update the player URL generation logic.\r\n## - 2026-07-30\r\n- fix security issue.\r\n## - 2026-07-16\r\n- fix bug about file hash validation.\r\n## - 2026-05-28\r\n- Initial release with dynamic frpc environment setup.\n\nFile v0.1.8:skill-card.md\n\n## Description:\n\nMediaSync-Claw lets an OpenClaw agent list and share local MP4 files through a Flask media service exposed over a public FRP tunnel for remote playback.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[yu-libin](https://clawhub.ai/user/yu-libin)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nExternal OpenClaw users use this skill to let an agent enumerate local MP4 files and return remote playback links through a connected chat channel. It is intended for personal media sharing, with the important caveat that the local service is exposed through a public third-party tunnel.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill automatically exposes a local unauthenticated media service through a public third-party tunnel.\n\nMitigation: Run it only when public sharing is intended, use a dedicated machine or VM, and store only non-sensitive MP4 files in the videos directory.\n\nRisk: Anyone who discovers the public subdomain may be able to access the exposed media service.\n\nMitigation: Prefer a version that adds authentication, explicit tunnel opt-in, and a way to disable public exposure by default.\n\nRisk: The skill downloads and executes a third-party FRP binary.\n\nMitigation: Use versions that verify pre-existing binaries and pinned dependencies, and review checksum updates before upgrading the FRP binary.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/yu-libin/skills/mediasync-claw)\n- [Publisher profile](https://clawhub.ai/user/yu-libin)\n- [FRP v0.65.0 release](https://github.com/fatedier/frp/releases/tag/v0.65.0)\n\n## Skill Output:\n\n**Output Type(s):** [text, guidance, configuration]\n\n**Output Format:** [JSON response containing human-readable text with media file names and playback links]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [The agent action accepts an optional query object and returns a single text field for conversational rendering.]\n\n## Skill Version(s):\n\n0.1.8 (source: server release metadata; artifact SKILL.md frontmatter says 1.0.8)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nFile v0.1.8:requirements.txt\n\nflask>=3.1.3\r\nrequests>=2.32.4\r\njinja2>=3.1.6\r\naiortc\r\nflask-socketio\n\nArchive v0.1.7: 11 files, 15596 bytes\n\nFiles: CHANGELOG.md (180b), media_file_util.py (694b), media_frp_util.py (7356b), media_server_flask.py (9947b), requirements.txt (69b), skill-card.md (2119b), skill.md (5663b), templates/medias.html (3637b), templates/player.html (9048b), uuid_config.py (981b), _meta.json (133b)\n\nFile v0.1.7:skill.md\n\n---\r\nname: MediaSync-Claw\r\nversion: 1.0.7\r\ndescription: This tool automatically downloads and executes the third-party 'frpc' binary from GitHub to establish an active outbound reverse tunnel. It exposes local file systems and port 8000 to the public internet via yunfrp.net subdomains. Additionally, it initiates outbound WebSocket/WebRTC signaling and connects to external STUN servers for peer-to-peer media streaming, enabling remote access and remote code execution capabilities by design.\r\nauthor: OpenClaw User\r\ntype: workspace\r\nlanguage: python\r\nentrypoint: media_server_flask.py\r\nrequires:\r\n  bins:\r\n    - python3\r\n    - uv\r\n  python:\r\n    - \"flask>=3.1.3\"\r\n    - \"requests>=2.32.4\"\r\n    - \"jinja2>=3.1.6\"\r\n    - \"aiortc\"\r\n    - \"flask-socketio\"\r\n\r\nactions:\r\n  - name: list_files\r\n    description: \"Call this tool when the user wants to view, list, play, or search for local videos or playlists (playlist/video library).\"\r\n    url: \"http://127.0.0.1:8000/api/list_files\"\r\n    method: \"POST\"\r\n    parameters:\r\n      type: object\r\n      properties:\r\n        query:\r\n          type: string\r\n          description: \"Keywords or filter conditions for the user query, optional.\"\r\n      required: []\r\n\r\npermissions:\r\n  - filesystem:read\r\n  - filesystem:write\r\n  - network:listen\r\n  - network:connect\r\n  - process:execute\r\n  - network:access:internal\r\n  - network:access:internet\r\n---\r\n\r\n# MediaSync-Claw\r\n\r\n## 🚀 Overview\r\n\r\n### Prerequisites:\r\n* **Environment**: Local OpenClaw environment successfully deployed.\r\n* **Antivirus**: Trust/add exception for `frpc.exe` in your security software if blocked.\r\n### Specific Steps:\r\n1. **Install**: Download and install the `MediaSync-Claw` skill via ClawHub.\r\n2. **Media Setup**: Create a `videos` directory inside this skill's folder and drop your MP4 files there.\r\n3.**Integration**: Link and configure your WhatsApp channel in OpenClaw.\r\n4. **Launch**: Start the `MediaSync-Claw` skill in OpenClaw.\r\n5. **Interact (LLM-Driven)**: Chat with the AI naturally in your channel. For example:\r\n   * *\"Show me my video list.\"*\r\n   * *\"Do I have any movie to watch?\"*\r\n   * *\"Play the video about cat.\"*\r\n6. **Play**: Click the generated link from the response to play your video.\r\n\r\n## 💡 LLM Agent Mode Active\r\nThis skill operates entirely at the **LLM Action/Tool execution level**. OpenClaw no longer intercepts requests via rigid keyword matching. Instead, the LLM intelligently understands user intents, translates fuzzy queries into structured API parameters, and hits your local Flask backend to fetch data.\r\n\r\n*Note: `media_server_flask.py` should return clean JSON data (e.g., file lists, file URLs). The LLM will automatically handle conversational rendering, typo correction, and personalized responses based on your data.*\r\n\r\n## 🔒 Security & Network Disclosure\r\n\r\n### ⚠️ Critical: FRP Tunnel Exposes Local Services to Public Internet\r\nThis skill **automatically** downloads and runs the **FRP (Fast Reverse Proxy) client (`frpc`)** upon startup. The `frpc` binary is fetched from GitHub Releases and establishes an outbound tunnel to a remote FRP server (`129.213.174.213:7000`), which in turn exposes your local media service (port 8000) to the **public internet** via a `*.yunfrp.net` subdomain.\r\n\r\n**This materially expands your attack surface.** Anyone who knows or discovers the public subdomain can attempt to access your media files and the Flask service running on your machine.\r\n\r\n### 1. Automatic Tunnel Behavior (No User Opt-in)\r\n* **Automatic on Startup**: The FRP tunnel starts automatically when `media_server_flask.py` runs. There is no prompt, no confirmation, and no environment-variable gate.\r\n* **Binary Download**: On first run, `frpc.exe` is downloaded silently from GitHub (`fatedier/frp` releases). Internet access is required.\r\n* **No Inbound Firewall Changes**: The tunnel is outbound-only; no inbound ports need to be opened on your firewall.\r\n\r\n### 2. Supply-Chain Risk: Downloaded Binary Execution\r\n* The skill downloads and executes a native binary (`frpc.exe`) from GitHub Releases. Compromise of the GitHub repository, the release artifact, or the network transport (MITM) could result in **arbitrary code execution** on your host with the same privileges as the Python process.\r\n* **Pinned SHA256 Verification**: The code includes hardcoded SHA256 checksums for both the zip archive and the extracted `frpc.exe` binary (version `0.65.0`). The download is rejected if either checksum does not match. This defends against transport tampering and corrupted downloads, but **does not protect against a compromise of the upstream GitHub repository or release**.\r\n* **Version-Locked**: The FRP version is pinned at `0.65.0`. Upgrading requires a code change and SHA256 re-verification. This prevents silent upgrades to potentially compromised newer versions.\r\n\r\n### 3. Authentication Status\r\n* **No Authentication Implemented**: The Flask server currently has **no HTTP Basic Auth, no token mechanism, and no access control**. All API routes and media endpoints are publicly accessible to anyone who reaches the server — whether via LAN or the FRP tunnel.\r\n* **Risk**: An unauthenticated third party who discovers the `*.yunfrp.net` subdomain can enumerate and download media files from your machine.\r\n\r\n### 4. Remote Server Trust\r\n* The FRP server at `129.213.174.213:7000` is a third-party relay. All traffic between the public internet and your local service passes through this server.\r\n* The FRP tunnel operates in HTTP mode (no TLS termination by FRP server).\r\n* You must trust that this FRP server operator will not inspect, log, or tamper with your traffic.\n\nFile v0.1.7:_meta.json\n\n{\n  \"ownerId\": \"kn723yj2g3pgy4vx13sg58hyk187z678\",\n  \"slug\": \"mediasync-claw\",\n  \"version\": \"0.1.7\",\n  \"publishedAt\": 1785394465518\n}\n\nFile v0.1.7:CHANGELOG.md\n\n# Changelog\r\n## - 2026-07-30\r\n- fix security issue.\r\n## - 2026-07-16\r\n- fix bug about file hash validation.\r\n## - 2026-05-28\r\n- Initial release with dynamic frpc environment setup.\n\nFile v0.1.7:skill-card.md\n\n## Description: <br>\nMediaSync-Claw lets an OpenClaw agent list local MP4 videos and return playback links through a Flask media server with FRP/WebRTC remote access. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[yu-libin](https://clawhub.ai/user/yu-libin) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nOpenClaw users use this skill to expose a local MP4 folder to an agent action that lists media and returns playable links for chat-driven playback. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill can publish a local media server without authentication and expose local files over the public internet. <br>\nMitigation: Use only a dedicated videos folder containing non-sensitive files, and do not run the skill with access to private data. <br>\nRisk: The skill uses a third-party FRP relay for public access to the local service. <br>\nMitigation: Install only when public relay access is intentional, and prefer a version with explicit tunnel opt-in, authentication, strict origin checks, and path allowlisting. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/yu-libin/skills/mediasync-claw) <br>\n- [Publisher profile](https://clawhub.ai/user/yu-libin) <br>\n- [FRP v0.65.0 release](https://github.com/fatedier/frp/releases/tag/v0.65.0) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, API calls] <br>\n**Output Format:** [JSON API response containing Markdown-formatted text and playback links] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Lists MP4 files from the skill's local videos directory and returns public playback links.] <br>\n\n## Skill Version(s): <br>\n0.1.7 (source: server release metadata; artifact frontmatter says 1.0.7) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nFile v0.1.7:requirements.txt\n\nflask>=3.1.3\r\nrequests>=2.32.4\r\njinja2>=3.1.6\r\naiortc\r\nflask-socketio\n\nArchive v0.1.5: 11 files, 15302 bytes\n\nFiles: CHANGELOG.md (140b), media_file_util.py (694b), media_frp_util.py (7356b), media_server_flask.py (9867b), requirements.txt (54b), skill-card.md (2263b), skill.md (4969b), templates/medias.html (3637b), templates/player.html (9048b), uuid_config.py (981b), _meta.json (133b)\n\nFile v0.1.5:skill.md\n\n---\r\nname: MediaSync-Claw\r\nversion: 1.0.5\r\ndescription: A media file server that serves multimedia files with FRP support\r\nauthor: OpenClaw User\r\ntype: workspace\r\nlanguage: python\r\nentrypoint: media_server_flask.py\r\nrequires:\r\n  bins:\r\n    - python3\r\n    - uv\r\n  python:\r\n    - \"flask>=2.0.1\"\r\n    - \"requests\"\r\n    - \"jinja2\"\r\n    - \"aiortc\"\r\n    - \"flask-socketio\"\r\ntriggers:\r\n  - type: keyword\r\n    values: [\"playlist\", \"media list\", \"show videos\", \"list files\", \"media pocket\", \"my media\", \"video library\", \"media gallery\"]\r\n    url: \"http://local.flask.service:8000/api/openclaw\"\r\n    method: \"POST\"\r\n\r\npermissions:\r\n  - filesystem:read\r\n  - filesystem:write\r\n  - network:listen\r\n  - network:connect\r\n  - process:execute\r\n  - network:access:internal\r\n  - network:access:internet\r\n---\r\n\r\n# MediaSync-Claw\r\n\r\n## 🚀 Overview\r\n\r\n### Prerequisites:\r\n* **Environment**: Local OpenClaw environment successfully deployed.\r\n* **Hosts Config**: Add `127.0.0.1 local.flask.service` to your system `hosts` file.\r\n* **Antivirus**: Trust/add exception for `frpc.exe` in your security software if blocked.\r\n### Specific Steps:\r\n1. **Install**: Download and install the `MediaSync-Claw` skill via ClawHub.\r\n2. **Media Setup**: Create a `videos` directory inside this skill's folder and drop your MP4 files there.\r\n3.**Integration**: Link and configure your WhatsApp channel in OpenClaw.\r\n4. **Launch**: Start the `MediaSync-Claw` skill in OpenClaw.\r\n5. **Trigger**: Send any of the following trigger phrases in WhatsApp to fetch your media list:\r\n   `playlist` | `media list` | `show videos` | `list files` | `media pocket` | `my media` | `video library` | `media gallery`\r\n6. **Play**: Click the generated link from the response to play your video.\r\n\r\n## 💡 Gateway Mode Active\r\nThis skill operates entirely at the gateway level. When a user sends a matched keyword, OpenClaw bypasses the LLM and forwards the request directly to the Flask backend to achieve low latency (<50ms).\r\n\r\n*Note: All response text formatting and custom error handling must be managed inside `media_server_flask.py`.*\r\n\r\n## 🔒 Security & Network Disclosure\r\n\r\n### ⚠️ Critical: FRP Tunnel Exposes Local Services to Public Internet\r\nThis skill **automatically** downloads and runs the **FRP (Fast Reverse Proxy) client (`frpc`)** upon startup. The `frpc` binary is fetched from GitHub Releases and establishes an outbound tunnel to a remote FRP server (`129.213.174.213:7000`), which in turn exposes your local media service (port 8000) to the **public internet** via a `*.yunfrp.net` subdomain.\r\n\r\n**This materially expands your attack surface.** Anyone who knows or discovers the public subdomain can attempt to access your media files and the Flask service running on your machine.\r\n\r\n### 1. Automatic Tunnel Behavior (No User Opt-in)\r\n* **Automatic on Startup**: The FRP tunnel starts automatically when `media_server_flask.py` runs. There is no prompt, no confirmation, and no environment-variable gate.\r\n* **Binary Download**: On first run, `frpc.exe` is downloaded silently from GitHub (`fatedier/frp` releases). Internet access is required.\r\n* **No Inbound Firewall Changes**: The tunnel is outbound-only; no inbound ports need to be opened on your firewall.\r\n\r\n### 2. Supply-Chain Risk: Downloaded Binary Execution\r\n* The skill downloads and executes a native binary (`frpc.exe`) from GitHub Releases. Compromise of the GitHub repository, the release artifact, or the network transport (MITM) could result in **arbitrary code execution** on your host with the same privileges as the Python process.\r\n* **Pinned SHA256 Verification**: The code includes hardcoded SHA256 checksums for both the zip archive and the extracted `frpc.exe` binary (version `0.65.0`). The download is rejected if either checksum does not match. This defends against transport tampering and corrupted downloads, but **does not protect against a compromise of the upstream GitHub repository or release**.\r\n* **Version-Locked**: The FRP version is pinned at `0.65.0`. Upgrading requires a code change and SHA256 re-verification. This prevents silent upgrades to potentially compromised newer versions.\r\n\r\n### 3. Authentication Status\r\n* **No Authentication Implemented**: The Flask server currently has **no HTTP Basic Auth, no token mechanism, and no access control**. All API routes and media endpoints are publicly accessible to anyone who reaches the server — whether via LAN or the FRP tunnel.\r\n* **Risk**: An unauthenticated third party who discovers the `*.yunfrp.net` subdomain can enumerate and download media files from your machine.\r\n\r\n### 4. Remote Server Trust\r\n* The FRP server at `129.213.174.213:7000` is a third-party relay. All traffic between the public internet and your local service passes through this server.\r\n* The FRP tunnel operates in HTTP mode (no TLS termination by FRP server).\r\n* You must trust that this FRP server operator will not inspect, log, or tamper with your traffic.\n\nFile v0.1.5:_meta.json\n\n{\n  \"ownerId\": \"kn723yj2g3pgy4vx13sg58hyk187z678\",\n  \"slug\": \"mediasync-claw\",\n  \"version\": \"0.1.5\",\n  \"publishedAt\": 1784779125656\n}\n\nFile v0.1.5:CHANGELOG.md\n\n# Changelog\r\n## - 2026-07-16\r\n- fix bug about file hash validation.\r\n## - 2026-05-28\r\n- Initial release with dynamic frpc environment setup.\n\nFile v0.1.5:skill-card.md\n\n## Description: <br>\nA media file server that serves multimedia files with FRP support. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[yu-libin](https://clawhub.ai/user/yu-libin) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nOpenClaw users use this skill to list local MP4 files and return playback links through a WhatsApp-triggered media workflow. It is intended for users who intentionally want a local media server exposed through an FRP domain. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill can expose a local unauthenticated media service through a public FRP domain. <br>\nMitigation: Run it only when public sharing is intended, restrict the media directory to files that may be public, and prefer a version with authentication and explicit tunnel opt-in. <br>\nRisk: The skill downloads and executes a native FRP client. <br>\nMitigation: Review the pinned FRP version and hashes before installation and use environments where executing the downloaded binary is acceptable. <br>\nRisk: Traffic depends on a third-party relay and public playback links. <br>\nMitigation: Avoid sensitive media, monitor the generated domain, and prefer deployments with restricted CORS, local-only default mode, and safe path handling. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/yu-libin/skills/mediasync-claw) <br>\n- [FRP v0.65.0 release](https://github.com/fatedier/frp/releases/tag/v0.65.0) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance] <br>\n**Output Format:** [Markdown text with media playlist links and setup guidance] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Returns playlist text containing media filenames and playback URLs.] <br>\n\n## Skill Version(s): <br>\n0.1.5 (source: server release evidence; artifact frontmatter reports 1.0.5) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nFile v0.1.5:requirements.txt\n\nflask>=2.0.1\r\nrequests\r\njinja2\r\naiortc\r\nflask-socketio\n\nArchive v0.1.3: 11 files, 15443 bytes\n\nFiles: CHANGELOG.md (84b), media_file_util.py (694b), media_frp_util.py (7357b), media_server_flask.py (9867b), requirements.txt (54b), skill-card.md (2648b), skill.md (4969b), templates/medias.html (3637b), templates/player.html (9048b), uuid_config.py (981b), _meta.json (133b)\n\nFile v0.1.3:skill.md\n\n---\r\nname: MediaSync-Claw\r\nversion: 1.0.1\r\ndescription: A media file server that serves multimedia files with FRP support\r\nauthor: OpenClaw User\r\ntype: workspace\r\nlanguage: python\r\nentrypoint: media_server_flask.py\r\nrequires:\r\n  bins:\r\n    - python3\r\n    - uv\r\n  python:\r\n    - \"flask>=2.0.1\"\r\n    - \"requests\"\r\n    - \"jinja2\"\r\n    - \"aiortc\"\r\n    - \"flask-socketio\"\r\ntriggers:\r\n  - type: keyword\r\n    values: [\"playlist\", \"media list\", \"show videos\", \"list files\", \"media pocket\", \"my media\", \"video library\", \"media gallery\"]\r\n    url: \"http://local.flask.service:8000/api/openclaw\"\r\n    method: \"POST\"\r\n\r\npermissions:\r\n  - filesystem:read\r\n  - filesystem:write\r\n  - network:listen\r\n  - network:connect\r\n  - process:execute\r\n  - network:access:internal\r\n  - network:access:internet\r\n---\r\n\r\n# MediaSync-Claw\r\n\r\n## 🚀 Overview\r\n\r\n### Prerequisites:\r\n* **Environment**: Local OpenClaw environment successfully deployed.\r\n* **Hosts Config**: Add `127.0.0.1 local.flask.service` to your system `hosts` file.\r\n* **Antivirus**: Trust/add exception for `frpc.exe` in your security software if blocked.\r\n### Specific Steps:\r\n1. **Install**: Download and install the `MediaSync-Claw` skill via ClawHub.\r\n2. **Media Setup**: Create a `videos` directory inside this skill's folder and drop your MP4 files there.\r\n3.**Integration**: Link and configure your WhatsApp channel in OpenClaw.\r\n4. **Launch**: Start the `MediaSync-Claw` skill in OpenClaw.\r\n5. **Trigger**: Send any of the following trigger phrases in WhatsApp to fetch your media list:\r\n   `playlist` | `media list` | `show videos` | `list files` | `media pocket` | `my media` | `video library` | `media gallery`\r\n6. **Play**: Click the generated link from the response to play your video.\r\n\r\n## 💡 Gateway Mode Active\r\nThis skill operates entirely at the gateway level. When a user sends a matched keyword, OpenClaw bypasses the LLM and forwards the request directly to the Flask backend to achieve low latency (<50ms).\r\n\r\n*Note: All response text formatting and custom error handling must be managed inside `media_server_flask.py`.*\r\n\r\n## 🔒 Security & Network Disclosure\r\n\r\n### ⚠️ Critical: FRP Tunnel Exposes Local Services to Public Internet\r\nThis skill **automatically** downloads and runs the **FRP (Fast Reverse Proxy) client (`frpc`)** upon startup. The `frpc` binary is fetched from GitHub Releases and establishes an outbound tunnel to a remote FRP server (`129.213.174.213:7000`), which in turn exposes your local media service (port 8000) to the **public internet** via a `*.yunfrp.net` subdomain.\r\n\r\n**This materially expands your attack surface.** Anyone who knows or discovers the public subdomain can attempt to access your media files and the Flask service running on your machine.\r\n\r\n### 1. Automatic Tunnel Behavior (No User Opt-in)\r\n* **Automatic on Startup**: The FRP tunnel starts automatically when `media_server_flask.py` runs. There is no prompt, no confirmation, and no environment-variable gate.\r\n* **Binary Download**: On first run, `frpc.exe` is downloaded silently from GitHub (`fatedier/frp` releases). Internet access is required.\r\n* **No Inbound Firewall Changes**: The tunnel is outbound-only; no inbound ports need to be opened on your firewall.\r\n\r\n### 2. Supply-Chain Risk: Downloaded Binary Execution\r\n* The skill downloads and executes a native binary (`frpc.exe`) from GitHub Releases. Compromise of the GitHub repository, the release artifact, or the network transport (MITM) could result in **arbitrary code execution** on your host with the same privileges as the Python process.\r\n* **Pinned SHA256 Verification**: The code includes hardcoded SHA256 checksums for both the zip archive and the extracted `frpc.exe` binary (version `0.65.0`). The download is rejected if either checksum does not match. This defends against transport tampering and corrupted downloads, but **does not protect against a compromise of the upstream GitHub repository or release**.\r\n* **Version-Locked**: The FRP version is pinned at `0.65.0`. Upgrading requires a code change and SHA256 re-verification. This prevents silent upgrades to potentially compromised newer versions.\r\n\r\n### 3. Authentication Status\r\n* **No Authentication Implemented**: The Flask server currently has **no HTTP Basic Auth, no token mechanism, and no access control**. All API routes and media endpoints are publicly accessible to anyone who reaches the server — whether via LAN or the FRP tunnel.\r\n* **Risk**: An unauthenticated third party who discovers the `*.yunfrp.net` subdomain can enumerate and download media files from your machine.\r\n\r\n### 4. Remote Server Trust\r\n* The FRP server at `129.213.174.213:7000` is a third-party relay. All traffic between the public internet and your local service passes through this server.\r\n* The FRP tunnel operates in HTTP mode (no TLS termination by FRP server).\r\n* You must trust that this FRP server operator will not inspect, log, or tamper with your traffic.\n\nFile v0.1.3:_meta.json\n\n{\n  \"ownerId\": \"kn723yj2g3pgy4vx13sg58hyk187z678\",\n  \"slug\": \"mediasync-claw\",\n  \"version\": \"0.1.3\",\n  \"publishedAt\": 1783480486709\n}\n\nFile v0.1.3:CHANGELOG.md\n\n# Changelog\r\n## - 2026-05-28\r\n- Initial release with dynamic frpc environment setup.\n\nFile v0.1.3:skill-card.md\n\n## Description: <br>\nA media file server that serves multimedia files with FRP support. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[yu-libin](https://clawhub.ai/user/yu-libin) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nExternal OpenClaw users trigger the skill from WhatsApp keywords to list and play MP4 files from a local media folder. The skill starts a local Flask and Socket.IO service and exposes media links through an FRP-backed playback flow. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill automatically opens a public unauthenticated FRP tunnel to the local media service. <br>\nMitigation: Run it only when public sharing is intended, add authentication or network restrictions before broader use, and disable or gate tunnel startup when remote access is not needed. <br>\nRisk: Anyone who discovers the public subdomain may access media endpoints and enumerate or download exposed files. <br>\nMitigation: Keep only intended MP4 files in the media directory, avoid storing private files near the skill directory, and add strict filename/path validation before deployment. <br>\nRisk: The skill downloads and executes a native FRP client from a third-party release source. <br>\nMitigation: Keep checksum verification enabled, re-verify hashes when upgrading FRP, and review the release source before allowing execution. <br>\nRisk: Traffic depends on a third-party FRP relay and the artifact describes HTTP tunnel behavior without authentication. <br>\nMitigation: Avoid sensitive media, prefer a trusted relay or TLS-protected access path, and monitor or stop the tunnel after use. <br>\n\n\n## Reference(s): <br>\n- [ClawHub Skill Page](https://clawhub.ai/yu-libin/skills/mediasync-claw) <br>\n- [FRP v0.65.0 Release](https://github.com/fatedier/frp/releases/tag/v0.65.0) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown] <br>\n**Output Format:** [JSON response containing Markdown-formatted playlist text and media playback links] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Lists MP4 files from the local videos directory and returns playback links for the FRP/WebRTC flow.] <br>\n\n## Skill Version(s): <br>\n0.1.3 (source: server release metadata; artifact frontmatter lists 1.0.1) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nFile v0.1.3:requirements.txt\n\nflask>=2.0.1\r\nrequests\r\njinja2\r\naiortc\r\nflask-socketio\n\nArchive v0.1.2: 12 files, 16327 bytes\n\nFiles: CHANGELOG.md (84b), media_file_util.py (694b), media_frp_util.py (7357b), media_server_flask.py (9867b), requirements.txt (54b), skill-card.md (2185b), skill.md (4037b), templates/medias.html (3637b), templates/player.html (9048b), uuid_config.py (981b), 说明.md (2218b), _meta.json (133b)\n\nFile v0.1.2:skill.md\n\n---\r\nname: MediaSync-Claw\r\nversion: 1.0.1\r\ndescription: A media file server that serves multimedia files with FRP support\r\nauthor: OpenClaw User\r\ntype: workspace\r\nlanguage: python\r\nentrypoint: media_server_flask.py\r\nrequires:\r\n  bins:\r\n    - python3\r\n    - uv\r\n  python:\r\n    - \"flask>=2.0.1\"\r\n    - \"requests\"\r\n    - \"jinja2\"\r\n    - \"aiortc\"\r\n    - \"flask-socketio\"\r\ntriggers:\r\n  - type: keyword\r\n    values: [\"playlist\", \"media list\", \"show videos\", \"list files\", \"media pocket\", \"my media\", \"video library\", \"media gallery\"]\r\n    url: \"http://local.flask.service:8000/api/openclaw\"\r\n    method: \"POST\"\r\n\r\npermissions:\r\n  - filesystem:read\r\n  - filesystem:write\r\n  - network:listen\r\n  - network:connect\r\n  - process:execute\r\n  - network:access:internal\r\n  - network:access:internet\r\n---\r\n\r\n# MediaSync-Claw\r\n\r\n## 💡 Gateway Mode Active\r\nThis skill operates entirely at the gateway level. When a user sends a matched keyword, OpenClaw bypasses the LLM and forwards the request directly to the Flask backend to achieve low latency (<50ms).\r\n\r\n*Note: All response text formatting and custom error handling must be managed inside `media_server_flask.py`.*\r\n\r\n## 🔒 Security & Network Disclosure\r\n\r\n### ⚠️ Critical: FRP Tunnel Exposes Local Services to Public Internet\r\nThis skill **automatically** downloads and runs the **FRP (Fast Reverse Proxy) client (`frpc`)** upon startup. The `frpc` binary is fetched from GitHub Releases and establishes an outbound tunnel to a remote FRP server (`129.213.174.213:7000`), which in turn exposes your local media service (port 8000) to the **public internet** via a `*.yunfrp.net` subdomain.\r\n\r\n**This materially expands your attack surface.** Anyone who knows or discovers the public subdomain can attempt to access your media files and the Flask service running on your machine.\r\n\r\n### 1. Automatic Tunnel Behavior (No User Opt-in)\r\n* **Automatic on Startup**: The FRP tunnel starts automatically when `media_server_flask.py` runs. There is no prompt, no confirmation, and no environment-variable gate.\r\n* **Binary Download**: On first run, `frpc.exe` is downloaded silently from GitHub (`fatedier/frp` releases). Internet access is required.\r\n* **No Inbound Firewall Changes**: The tunnel is outbound-only; no inbound ports need to be opened on your firewall.\r\n\r\n### 2. Supply-Chain Risk: Downloaded Binary Execution\r\n* The skill downloads and executes a native binary (`frpc.exe`) from GitHub Releases. Compromise of the GitHub repository, the release artifact, or the network transport (MITM) could result in **arbitrary code execution** on your host with the same privileges as the Python process.\r\n* **Pinned SHA256 Verification**: The code includes hardcoded SHA256 checksums for both the zip archive and the extracted `frpc.exe` binary (version `0.65.0`). The download is rejected if either checksum does not match. This defends against transport tampering and corrupted downloads, but **does not protect against a compromise of the upstream GitHub repository or release**.\r\n* **Version-Locked**: The FRP version is pinned at `0.65.0`. Upgrading requires a code change and SHA256 re-verification. This prevents silent upgrades to potentially compromised newer versions.\r\n\r\n### 3. Authentication Status\r\n* **No Authentication Implemented**: The Flask server currently has **no HTTP Basic Auth, no token mechanism, and no access control**. All API routes and media endpoints are publicly accessible to anyone who reaches the server — whether via LAN or the FRP tunnel.\r\n* **Risk**: An unauthenticated third party who discovers the `*.yunfrp.net` subdomain can enumerate and download media files from your machine.\r\n\r\n### 4. Remote Server Trust\r\n* The FRP server at `129.213.174.213:7000` is a third-party relay. All traffic between the public internet and your local service passes through this server.\r\n* The FRP tunnel operates in HTTP mode (no TLS termination by FRP server).\r\n* You must trust that this FRP server operator will not inspect, log, or tamper with your traffic.\n\nFile v0.1.2:_meta.json\n\n{\n  \"ownerId\": \"kn723yj2g3pgy4vx13sg58hyk187z678\",\n  \"slug\": \"mediasync-claw\",\n  \"version\": \"0.1.2\",\n  \"publishedAt\": 1782965176050\n}\n\nFile v0.1.2:CHANGELOG.md\n\n# Changelog\r\n## - 2026-05-28\r\n- Initial release with dynamic frpc environment setup.\n\nFile v0.1.2:skill-card.md\n\n## Description: <br>\nMediaSync Claw serves local MP4 media files through a Flask backend and FRP tunnel for remote playback. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[yu-libin](https://clawhub.ai/user/yu-libin) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nOpenClaw users and developers use this skill to expose a local media library, list playable MP4 files through keyword triggers, and return links for remote playback. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill can expose an unauthenticated local media service through a public FRP tunnel. <br>\nMitigation: Install only when public tunnel access is intended, add authentication before use, and disable or gate automatic FRP startup. <br>\nRisk: Insufficient file-access controls could expose media or nearby sensitive files. <br>\nMitigation: Restrict file requests to an allowlisted media directory and avoid storing sensitive files near the skill folder. <br>\nRisk: The skill downloads and runs an FRP client binary and depends on runtime Python packages. <br>\nMitigation: Verify the frpc binary, pinned checksums, and dependency versions before deployment. <br>\n\n\n## Reference(s): <br>\n- [ClawHub Skill Page](https://clawhub.ai/yu-libin/skills/mediasync-claw) <br>\n- [Skill Manifest](artifact/skill.md) <br>\n- [Usage Description](artifact/说明.md) <br>\n- [Release Changelog](artifact/CHANGELOG.md) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, configuration] <br>\n**Output Format:** [JSON response containing human-readable playlist text and playback links] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Starts a local Flask service and may generate FRP and UUID configuration files at runtime.] <br>\n\n## Skill Version(s): <br>\n0.1.2 (source: server release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nFile v0.1.2:说明.md\n\n### skill描述：\r\n一个功能全面的 OpenClaw 工作区技能，提供用于存储、管理和提供多媒体文件的媒体文件服务器。\r\n该服务器基于 Flask 构建，支持 HTTPS 协议，并与 FRP（快速反向代理）无缝集成以实现安全的远程访问。\r\n核心功能包括：对多媒体格式（视频mp4）的增强型 MIME 类型检测、带媒体分类的自定义目录列表、防止目录遍历攻击的 robust 安全措施，\r\n以及自动生成 FRP 配置文件。服务器同时提供本地网络访问和基于安全隧道的远程访问，非常适合在跨网络共享媒体库的同时保持数据安全性。\r\n\r\n### 使用前提：\r\n* hosts中设定127.0.0.1 local.flask.service\r\n* 在系统安全软件中添加例外（信任）frpc.exe, 我们保证frpc.exe是安全的\r\n\r\n### 使用步骤：\r\n1. 安装并运行本技能\r\n2. whatsapp中输入playlist、media list、show videos、list files等唤醒词\r\n3. 获取到可播放文件列表\r\n4. 点击文件链接切换ai播放器播放文件\r\n\r\n### skill description:\r\nA comprehensive OpenClaw workspace skill that provides a feature-rich media file server for storing, managing, and serving multimedia files. Built with Flask, this server supports HTTPS protocol and integrates seamlessly with FRP (Fast Reverse Proxy) for secure remote access. Key features include enhanced MIME type detection for media formats (video), custom directory listing with media categorization, robust security measures against directory traversal attacks, and automatic FRP configuration generation. The server offers both local network access and secure tunnel-based remote access through proxy protocols, making it ideal for sharing media libraries across networks while maintaining data security.\r\n\r\n### Prerequisites:\r\n* Set 127.0.0.1 local.flask.service in the hosts file.\r\n* Add an exception (trust) for frpc.exe in the system security software, we assure frpc.exe is safe.\r\n\r\n### Usage Steps:\r\n1. Install and run this skill\r\n2. Enter trigger words such as \"playlist\", \"media list\", \"show videos\", or \"list files\" in WhatsApp\r\n3. Receive a list of playable files\r\n4. Click on a file link to switch to the AI player and play the file\n\nFile v0.1.2:requirements.txt\n\nflask>=2.0.1\r\nrequests\r\njinja2\r\naiortc\r\nflask-socketio\n\nArchive v0.1.1: 12 files, 16361 bytes\n\nFiles: CHANGELOG.md (84b), media_file_util.py (694b), media_frp_util.py (7357b), media_server_flask.py (9868b), requirements.txt (54b), skill-card.md (2217b), skill.md (4037b), templates/medias.html (3637b), templates/player.html (9048b), uuid_config.py (981b), 说明.md (2218b), _meta.json (133b)\n\nFile v0.1.1:skill.md\n\n---\r\nname: MediaSync-Claw\r\nversion: 1.0.1\r\ndescription: A media file server that serves multimedia files with FRP support\r\nauthor: OpenClaw User\r\ntype: workspace\r\nlanguage: python\r\nentrypoint: media_server_flask.py\r\nrequires:\r\n  bins:\r\n    - python3\r\n    - uv\r\n  python:\r\n    - \"flask>=2.0.1\"\r\n    - \"requests\"\r\n    - \"jinja2\"\r\n    - \"aiortc\"\r\n    - \"flask-socketio\"\r\ntriggers:\r\n  - type: keyword\r\n    values: [\"playlist\", \"media list\", \"show videos\", \"list files\", \"media pocket\", \"my media\", \"video library\", \"media gallery\"]\r\n    url: \"http://local.flask.service:8000/api/openclaw\"\r\n    method: \"POST\"\r\n\r\npermissions:\r\n  - filesystem:read\r\n  - filesystem:write\r\n  - network:listen\r\n  - network:connect\r\n  - process:execute\r\n  - network:access:internal\r\n  - network:access:internet\r\n---\r\n\r\n# MediaSync-Claw\r\n\r\n## 💡 Gateway Mode Active\r\nThis skill operates entirely at the gateway level. When a user sends a matched keyword, OpenClaw bypasses the LLM and forwards the request directly to the Flask backend to achieve low latency (<50ms).\r\n\r\n*Note: All response text formatting and custom error handling must be managed inside `media_server_flask.py`.*\r\n\r\n## 🔒 Security & Network Disclosure\r\n\r\n### ⚠️ Critical: FRP Tunnel Exposes Local Services to Public Internet\r\nThis skill **automatically** downloads and runs the **FRP (Fast Reverse Proxy) client (`frpc`)** upon startup. The `frpc` binary is fetched from GitHub Releases and establishes an outbound tunnel to a remote FRP server (`129.213.174.213:7000`), which in turn exposes your local media service (port 8000) to the **public internet** via a `*.yunfrp.net` subdomain.\r\n\r\n**This materially expands your attack surface.** Anyone who knows or discovers the public subdomain can attempt to access your media files and the Flask service running on your machine.\r\n\r\n### 1. Automatic Tunnel Behavior (No User Opt-in)\r\n* **Automatic on Startup**: The FRP tunnel starts automatically when `media_server_flask.py` runs. There is no prompt, no confirmation, and no environment-variable gate.\r\n* **Binary Download**: On first run, `frpc.exe` is downloaded silently from GitHub (`fatedier/frp` releases). Internet access is required.\r\n* **No Inbound Firewall Changes**: The tunnel is outbound-only; no inbound ports need to be opened on your firewall.\r\n\r\n### 2. Supply-Chain Risk: Downloaded Binary Execution\r\n* The skill downloads and executes a native binary (`frpc.exe`) from GitHub Releases. Compromise of the GitHub repository, the release artifact, or the network transport (MITM) could result in **arbitrary code execution** on your host with the same privileges as the Python process.\r\n* **Pinned SHA256 Verification**: The code includes hardcoded SHA256 checksums for both the zip archive and the extracted `frpc.exe` binary (version `0.65.0`). The download is rejected if either checksum does not match. This defends against transport tampering and corrupted downloads, but **does not protect against a compromise of the upstream GitHub repository or release**.\r\n* **Version-Locked**: The FRP version is pinned at `0.65.0`. Upgrading requires a code change and SHA256 re-verification. This prevents silent upgrades to potentially compromised newer versions.\r\n\r\n### 3. Authentication Status\r\n* **No Authentication Implemented**: The Flask server currently has **no HTTP Basic Auth, no token mechanism, and no access control**. All API routes and media endpoints are publicly accessible to anyone who reaches the server — whether via LAN or the FRP tunnel.\r\n* **Risk**: An unauthenticated third party who discovers the `*.yunfrp.net` subdomain can enumerate and download media files from your machine.\r\n\r\n### 4. Remote Server Trust\r\n* The FRP server at `129.213.174.213:7000` is a third-party relay. All traffic between the public internet and your local service passes through this server.\r\n* The FRP tunnel operates in HTTP mode (no TLS termination by FRP server).\r\n* You must trust that this FRP server operator will not inspect, log, or tamper with your traffic.\n\nFile v0.1.1:_meta.json\n\n{\n  \"ownerId\": \"kn723yj2g3pgy4vx13sg58hyk187z678\",\n  \"slug\": \"mediasync-claw\",\n  \"version\": \"0.1.1\",\n  \"publishedAt\": 1782963546035\n}\n\nFile v0.1.1:CHANGELOG.md\n\n# Changelog\r\n## - 2026-05-28\r\n- Initial release with dynamic frpc environment setup.\n\nFile v0.1.1:skill-card.md\n\n## Description: <br>\nA media file server that serves multimedia files with FRP support. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[yu-libin](https://clawhub.ai/user/yu-libin) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nExternal OpenClaw users use this workspace skill to list local MP4 media files and receive playable media links through a Flask service with FRP-based remote access. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill can expose local media through a public, unauthenticated service. <br>\nMitigation: Use it only for non-sensitive media, place it behind authentication where possible, and deploy it only when public sharing is intentional. <br>\nRisk: The skill uses a third-party FRP relay and public STUN/CDN services. <br>\nMitigation: Confirm that these services are acceptable for the deployment and avoid sharing content that must not traverse third-party infrastructure. <br>\nRisk: The skill downloads and runs a tunnel binary without a separate opt-in. <br>\nMitigation: Require explicit operator approval before starting FRP, keep dependencies patched and pinned, and avoid adding security-software exceptions unless the binary is independently verified. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/yu-libin/skills/mediasync-claw) <br>\n- [FRP v0.65.0 release](https://github.com/fatedier/frp/releases/tag/v0.65.0) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, JSON] <br>\n**Output Format:** [JSON response containing user-facing playlist text and media playback links] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Returns available MP4 media entries and public playback URLs when media files are present.] <br>\n\n## Skill Version(s): <br>\n0.1.1 (source: server release metadata; artifact frontmatter reports 1.0.1) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nFile v0.1.1:说明.md\n\n### skill描述：\r\n一个功能全面的 OpenClaw 工作区技能，提供用于存储、管理和提供多媒体文件的媒体文件服务器。\r\n该服务器基于 Flask 构建，支持 HTTPS 协议，并与 FRP（快速反向代理）无缝集成以实现安全的远程访问。\r\n核心功能包括：对多媒体格式（视频mp4）的增强型 MIME 类型检测、带媒体分类的自定义目录列表、防止目录遍历攻击的 robust 安全措施，\r\n以及自动生成 FRP 配置文件。服务器同时提供本地网络访问和基于安全隧道的远程访问，非常适合在跨网络共享媒体库的同时保持数据安全性。\r\n\r\n### 使用前提：\r\n* hosts中设定127.0.0.1 local.flask.service\r\n* 在系统安全软件中添加例外（信任）frpc.exe, 我们保证frpc.exe是安全的\r\n\r\n### 使用步骤：\r\n1. 安装并运行本技能\r\n2. whatsapp中输入playlist、media list、show videos、list files等唤醒词\r\n3. 获取到可播放文件列表\r\n4. 点击文件链接切换ai播放器播放文件\r\n\r\n### skill description:\r\nA comprehensive OpenClaw workspace skill that provides a feature-rich media file server for storing, managing, and serving multimedia files. Built with Flask, this server supports HTTPS protocol and integrates seamlessly with FRP (Fast Reverse Proxy) for secure remote access. Key features include enhanced MIME type detection for media formats (video), custom directory listing with media categorization, robust security measures against directory traversal attacks, and automatic FRP configuration generation. The server offers both local network access and secure tunnel-based remote access through proxy protocols, making it ideal for sharing media libraries across networks while maintaining data security.\r\n\r\n### Prerequisites:\r\n* Set 127.0.0.1 local.flask.service in the hosts file.\r\n* Add an exception (trust) for frpc.exe in the system security software, we assure frpc.exe is safe.\r\n\r\n### Usage Steps:\r\n1. Install and run this skill\r\n2. Enter trigger words such as \"playlist\", \"media list\", \"show videos\", or \"list files\" in WhatsApp\r\n3. Receive a list of playable files\r\n4. Click on a file link to switch to the AI player and play the file\n\nFile v0.1.1:requirements.txt\n\nflask>=2.0.1\r\nrequests\r\njinja2\r\naiortc\r\nflask-socketio\n\nArchive v0.1.0: 11 files, 12168 bytes\n\nFiles: CHANGELOG.md (82b), media_file_util.py (670b), media_frp_util.py (3939b), media_server_flask.py (9575b), requirements.txt (50b), skill-card.md (2068b), skill.md (1118b), templates/medias.html (3494b), templates/player.html (8702b), uuid_config.py (954b), _meta.json (133b)\n\nFile v0.1.0:skill.md\n\n---\nname: MediaSync-Claw\nversion: 1.0.0\ndescription: A media file server that serves multimedia files with FRP support\nauthor: OpenClaw User\ntype: workspace\nlanguage: python\nentrypoint: media_server_flask.py\nrequires:\n  bins:\n    - python3\n    - uv\n  python:\n    - \"flask>=2.0.1\"\n    - \"requests\"\n    - \"jinja2\"\n    - \"aiortc\"\n    - \"flask-socketio\"\ntriggers:\n  - type: keyword\n    values: [\"playlist\", \"media list\", \"show videos\", \"list files\", \"media pocket\", \"my media\", \"video library\", \"media gallery\"]\n    url: \"http://local.flask.service:8000/api/openclaw\"\n    method: \"POST\"\n\npermissions:\n  - filesystem:read\n  - filesystem:write\n  - network:listen\n  - network:connect\n  - process:execute\n  - network:access:internal\n  - network:access:internet\n---\n\n# MediaSync-Claw\n\n### 💡 Gateway Mode Active\nThis skill operates entirely at the gateway level. When a user sends a matched keyword, OpenClaw bypasses the LLM and forwards the request directly to the Flask backend to achieve low latency (<50ms).\n\n*Note: All response text formatting and custom error handling must be managed inside `media_server_flask.py`.*\n\nFile v0.1.0:_meta.json\n\n{\n  \"ownerId\": \"kn723yj2g3pgy4vx13sg58hyk187z678\",\n  \"slug\": \"mediasync-claw\",\n  \"version\": \"0.1.0\",\n  \"publishedAt\": 1781694868800\n}\n\nFile v0.1.0:CHANGELOG.md\n\n# Changelog\n## - 2026-05-28\n- Initial release with dynamic frpc environment setup.\n\nFile v0.1.0:skill-card.md\n\n## Description: <br>\nA media file server that serves multimedia files with FRP support. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[yu-libin](https://clawhub.ai/user/yu-libin) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nExternal users and developers use this skill to expose a local media library through an OpenClaw-triggered Flask service and return playlist or player links for available video files. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill can expose local media files through an unauthenticated public tunnel. <br>\nMitigation: Run it only in an isolated directory containing non-sensitive media, require authentication and strict path validation before deployment, and disable automatic tunneling unless remote access is explicitly needed. <br>\nRisk: The skill can download and run an unverified FRP executable. <br>\nMitigation: Use a reviewed FRP binary from a trusted source with pinned integrity checks before allowing execution. <br>\n\n\n## Reference(s): <br>\n- [MediaSync Claw on ClawHub](https://clawhub.ai/yu-libin/mediasync-claw) <br>\n- [Server-resolved GitHub provenance](https://github.com/YUN-POLYMERIZITION-GLOBAL-PTE-LTD/MediaSync-Claw.git) <br>\n- [Publisher profile](https://clawhub.ai/user/yu-libin) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, configuration] <br>\n**Output Format:** [JSON response containing human-facing playlist text and HTTPS player URLs] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May create local FRP configuration and serve MP4 files from the skill's media directory when run.] <br>\n\n## Skill Version(s): <br>\n0.1.0 (source: server release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nFile v0.1.0:requirements.txt\n\nflask>=2.0.1\nrequests\njinja2\naiortc\nflask-socketio","readmeExcerpt":"Skill: MediaSync-Claw Owner: yu-libin Summary: This tool automatically downloads and executes the third-party 'frpc' binary from GitHub to establish an active outbound reverse tunnel. It exposes local file systems and port 8000 to the public internet via yunfrp.net subdomains. Additionally, it initiates outbound WebSocket/WebRTC signaling and co Tags: latest:0.1.11 Version history: v0.1.11 | 2026-09-10T04:52:42.115Z ","codeSnippets":[],"executableExamples":[],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\r\nname: MediaSync-Claw\r\nversion: 1.0.11\r\ndescription: This tool automatically downloads and executes the third-party 'frpc' binary from GitHub to establish an active outbound reverse tunnel. It exposes local file systems and port 8000 to the public internet via yunfrp.net subdomains. Additionally, it initiates outbound WebSocket/WebRTC signaling and connects to external STUN servers for peer-to-peer media streaming, enabling remote file access.\r\nauthor: OpenClaw User\r\ntype: workspace\r\nlanguage: python\r\nentrypoint: media_server_flask.py\r\nrequires:\r\n  bins:\r\n    - python3\r\n    - uv\r\n  python:\r\n    - \"flask>=3.1.3\"\r\n    - \"requests>=2.32.4\"\r\n    - \"jinja2>=3.1.6\"\r\n    - \"aiortc\"\r\n    - \"aiofiles\"\r\n    - \"flask-socketio\"\r\n\r\nactions:\r\n  - name: list_files\r\n    description: \"Call this tool when the user wants to view, list, play, or search for local videos or playlists (playlist/video library).\"\r\n    url: \"http://127.0.0.1:8000/api/list_files\"\r\n    method: \"POST\"\r\n    parameters:\r\n      type: object\r\n      properties:\r\n        query:\r\n          type: string\r\n          description: \"Keywords or filter conditions for the user query, optional.\"\r\n      required: []\r\n\r\npermissions:\r\n  - filesystem:read\r\n  - filesystem:write\r\n  - network:listen\r\n  - network:connect\r\n  - process:execute\r\n  - network:access:internal\r\n  - network:access:internet\r\n---\r\n\r\n# MediaSync-Claw\r\n\r\n## 🚀 Overview\r\n\r\n### Prerequisites:\r\n* **Environment**: Local OpenClaw environment successfully deployed.\r\n* **Windows**: Trust/add exception for `frpc.exe` in your security software if blocked.\r\n* **macOS**: On first run, macOS Gatekeeper may block the downloaded `frpc` binary. Go to **System Preferences > Security & Privacy** and click \"Allow Anyway\" if prompted.\r\n### Specific Steps:\r\n1. **Install**: Download and install the `MediaSync-Claw` skill via ClawHub.\r\n2. **Media Setup**: Create a `videos` directory inside this skill's folder and drop your MP4 files there.\r\n3.**Integration**: Link and configure your WhatsApp channel in OpenClaw.\r\n4. **Launch**: Start the `MediaSync-Claw` skill in OpenClaw.\r\n5. **Interact (LLM-Driven)**: Chat with the AI naturally in your channel. For example:\r\n   * *\"Show me my video list.\"*\r\n   * *\"Do I have any movie to watch?\"*\r\n   * *\"Play the video about cat.\"*\r\n6. **Play**: Click the generated link from the response to play your video.\r\n\r\n## 💡 LLM Agent Mode Active\r\nThis skill operates entirely at the **LLM Action/Tool execution level**. OpenClaw no longer intercepts requests via rigid keyword matching. Instead, the LLM intelligently understands user intents, translates fuzzy queries into structured API parameters, and hits your local Flask backend to fetch data.\r\n\r\n*Note: `media_server_flask.py` should return clean JSON data (e.g., file lists, file URLs). The LLM will automatically handle conversational rendering, typo correction, and personalized responses based on your data.*\r\n\r\n## 🔒 Security & Network Disclosure\r\n\r\n### ⚠️ Critical: FRP Tunnel Expose"},{"path":"README.md","content":"<div align=\"center\">\n\n# MediaSync-Claw: Remote P2P Media Server & Streaming Skill for OpenClaw\n\n**[ 🌐 Visit Official Website & Full Documentation ](https://poly-ai.chat/mediasync-claw)**\n\n[English](README.md) | [简体中文](README_ZH.md) | [日本語](README_JA.md) | [Deutsch](README_DE.md) | [Español](README_ES.md)\n\n</div>\n\n---\n\n## 📖 Overview & Core Value\n\n**MediaSync-Claw** is a dedicated **OpenClaw Skill** and **Remote P2P Media Server** developed by [Poly AI](https://poly-ai.chat). \n\nIts core value is enabling users to access, index, and stream their local home PC media library **anytime, anywhere via WhatsApp** using the OpenClaw AI agent. The generated media list supports seamless playback with the **AIpollo Player** via high-speed P2P tunneling. \n\nFor advanced configurations, enterprise support, and the latest updates, please visit our **[Official Product Page](https://poly-ai.chat/mediasync-claw)**.\n\n---\n\n## ⚙️ Prerequisites\n\n* **OpenClaw**: Ensure OpenClaw is deployed and running in your local environment.\n* **Firewall / Antivirus Whitelist**: Add an exception (trust rule) for `frpc.exe` in your Windows Defender or antivirus software. *We ensure that `frpc.exe` is completely safe and unaltered.*\n\n---\n\n## 🚀 Step-by-Step Installation & Usage\n\n1. **Download & Install**: Clone or download this repository into your OpenClaw skills directory.\n2. **Setup Media Library**: Create a `videos` directory inside the skill folder and place the MP4 video files you wish to access remotely into it.\n3. **Configure WhatsApp**: Connect and configure your WhatsApp channel within OpenClaw.\n4. **Launch Skill**: Run the MediaSync-Claw skill in OpenClaw.\n5. **Remote Command via WhatsApp**: In your WhatsApp chat, send natural language requests (e.g., when you want to view, list, search, or play local videos/playlists from your video library) to trigger this skill and generate the media list.\n6. **One-Click Playback**: Click the generated link from the media list to start streaming on AIpollo Player.\n\n---\n\n## 🔒 Security Disclosures & Risk Management\n\n### Risk 1: Public Network Routing via FRP Reverse Proxy\nTo provide convenient remote media streaming across restricted local networks, this skill establishes an outbound tunnel using the FRP (Fast Reverse Proxy) client (`frpc`) to connect with an `frps` relay server. This enables public routing for your local media service via the `*.yunfrp.net` domain.\n\n### Risk 2: Plaintext HTTP Transmission & P2P Stream Architecture\nThe actual video streaming of this skill relies on **P2P direct connections**. HTTP is strictly used for transmitting lightweight control instructions and never carries sensitive personal user data.\n\n### Risk 3: Automated `frpc.exe` Binary Retrieval\nTo support cross-network NAT traversal and reverse proxying, the required `frpc.exe` binary is fetched directly from official GitHub releases to ensure maximum supply-chain integrity and security.\n\n---\n\n## 🛡️ Best Practice Recommendations\n\n* **Dedicated Server / Vi"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn723yj2g3pgy4vx13sg58hyk187z678\",\n  \"slug\": \"mediasync-claw\",\n  \"version\": \"0.1.11\",\n  \"publishedAt\": 1789015962115\n}"},{"path":"CHANGELOG.md","content":"# Changelog\r\n## - 2026-08-24\r\n- fix path issue\r\n## - 2026-08-20\r\n- fix security issue\r\n## - 2026-08-14\r\n- update the player URL generation logic.\r\n## - 2026-07-30\r\n- fix security issue.\r\n## - 2026-07-16\r\n- fix bug about file hash validation.\r\n## - 2026-05-28\r\n- Initial release with dynamic frpc environment setup."},{"path":"README_DE.md","content":"<div align=\"center\">\n\n# MediaSync-Claw: Remote P2P-Medienserver & Streaming-Skill für OpenClaw\n\n[English](README.md) | [简体中文](README_ZH.md) | [日本語](README_JA.md) | [Deutsch](README_DE.md) | [Español](README_ES.md)\n\n</div>\n\n---\n\n## 📖 Übersicht & Kernfunktionalität\n\n**MediaSync-Claw** ist ein dedizierter **OpenClaw-Skill** und **P2P-Medienserver** für das persönliche Video- und Audiostreaming im Homelab- und Self-Hosted-Bereich.\n\nÜber die Anbindung von OpenClaw an WhatsApp können Sie jederzeit und von überall auf die Medienbibliothek Ihres lokalen Heim-PCs zugreifen. Die generierte Medienliste ermöglicht ein schnelles, verlustfreies P2P-Streaming über den **AIpollo Player**.\n\n---\n\n## ⚙️ Systemanforderungen\n\n* **OpenClaw**: OpenClaw ist lokal installiert und einsatzbereit.\n* **Firewall- / Antivirus-Freigabe**: Fügen Sie `frpc.exe` als Ausnahme in Windows Defender oder Ihrer Sicherheitssoftware hinzu. *Wir garantieren, dass `frpc.exe` absolut sicher und ungepatcht ist.*\n\n---\n\n## 🚀 Schritt-für-Schritt Installationsanleitung\n\n1. **Download & Installation**: Klonen oder laden Sie dieses Repository in das Skills-Verzeichnis von OpenClaw herunter.\n2. **Medienordner anlegen**: Erstellen Sie im Skill-Verzeichnis einen Ordner namens `videos` und hinterlegen Sie dort die MP4-Videodateien.\n3. **WhatsApp konfigurieren**: Richten Sie die WhatsApp-Schnittstelle in OpenClaw ein.\n4. **Skill ausführen**: Starten Sie den MediaSync-Claw-Skill in OpenClaw.\n5. **Fernsteuerung via WhatsApp**: Senden Sie einen Befehl über WhatsApp (z. B. wenn Sie Videos auflisten, suchen oder abspielen möchten), um die Medienliste abzurufen.\n6. **Wiedergabe starten**: Klicken Sie auf den generierten Link in der Medienliste, um den Stream im AIpollo Player zu starten.\n\n---\n\n## 🔒 Sicherheits- und Risikohinweise\n\n### Risiko 1: Öffentlicher Netzwerkzugriff via FRP-Reverse-Proxy\nUm Medien hinter NAT-Routern und Firewalls erreichbar zu machen, baut der FRP-Client (`frpc`) einen ausgehenden Tunnel zu einem Relay-Server (`frps`) auf. Dadurch wird der lokale Dienst über die Domain `*.yunfrp.net` erreichbar.\n\n### Risiko 2: HTTP-Klartextübertragung & P2P-Streaming\nDas eigentliche Videostreaming erfolgt über eine **direkte P2P-Verbindung**. Über HTTP werden ausschließlich Steuerbefehle übertragen; es werden keine sensiblen Benutzerdaten übertragen.\n\n### Risiko 3: Bezug der ausführbaren Datei `frpc.exe`\nUm die Integrität der Lieferkette zu gewährleisten, wird die Binärdatei `frpc.exe` direkt aus den offiziellen GitHub-Releases bezogen.\n\n---\n\n## 🛡️ Sicherheitsempfehlungen\n\n* **Dedizierte Hardware / Virtuelle Maschine**: Für maximale Sicherheit empfehlen wir, diesen Dienst auf einem separaten Server (z. B. Homelab/NAS) oder in einer isolierten virtuellen Maschine (VM) zu betreiben.\n* **Regelmäßige Updates**: Halten Sie Ihr Betriebssystem und Ihre OpenClaw-Umgebung stets auf dem neuesten Stand.\n\n---\n\n## 💻 Plattformkompatibilität\n\n* **Aktuell unterstützt**: Windows (x64)\n* **In Entwicklung**: Linux /"}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"This tool automatically downloads and executes the third-party 'frpc' binary from GitHub to establish an active outbound reverse tunnel. It exposes local file systems and port 8000 to the public internet via yunfrp.net subdomains. Additionally, it initiates outbound WebSocket/WebRTC signaling and co Skill: MediaSync-Claw Owner: yu-libin Summary: This tool automatically downloads and executes the third-party 'frpc' binary from GitHub to establish an active outbound reverse tunnel. It exposes local file systems and port 8000 to the public internet via yunfrp.net subdomains. Additionally, it initiates outbound WebSocket/WebRTC signaling and co Tags: latest:0.1.11 Version history: v0.1.11 | 2026-09-10T04:52:42.115Z","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1871,"uniquenessScore":50,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-10T23:49:47.451Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-10T23:49:47.451Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-11T03:54:55.628Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}