| metadata | {"displayName":"命理大师","version":"1.2.0","keywords":"八字, 紫微斗数, 奇门遁甲, 六爻, 梅花易数, 塔罗, 星盘, 九宫飞星, 今日运势, 每日运程, 合婚, 择吉, 生命灵数, 风水, 算命, BaZi, ZiWei, QiMen, Tarot, feng shui, I Ching, numerology, daily horoscope","openclaw":{"emoji":"☯️","skillKey":"university-applications","runtime":{"node":">=18","python3":true},"install":[{"kind":"node","package":"iztro"}],"env":[],"security":{"network":{"default":"none","optional":[{"feature":"liuyao HTML LLM divination (user-initiated, in-browser, OFF by default)","allowed-endpoints":["https://api.openai.com","https://api.anthropic.com","https://api.deepseek.com"],"custom-endpoint":"only after explicit in-UI consent dialog; HTTPS-only, no IP/localhost auto-trust","data-sent":"only the hexagram and the user's typed question; no profile, no env vars, no file paths","credential":"user-provided LLM API key, entered at runtime, stored in browser localStorage only"},{"feature":"liuyao HTML Google Fonts (commented out by default)","endpoint":"https://fonts.googleapis.com","data-sent":"none beyond standard font request","credential":"none"}]},"credentials":{"bundled":"none","required":"none","user-optional":["LLM API key for liuyao/index.html divination feature (scope it to a separate limited key, never reused)"]},"push-mechanism":"openclaw-ipc","push-optin":true,"push-default-state":"disabled","data-retention":{"location":"local filesystem under data/profiles/ and data/push-log.json","remote-upload":"none","user-controls":["view: node scripts/profile.js show <userId>","list: node scripts/profile.js list","edit: node scripts/profile.js save <userId> <field> <value>","delete: node scripts/profile.js delete <userId>","disable push: node scripts/push-toggle.js off <userId>"]},"notes":"All bundled scripts perform local computation only — no fetch, axios,\nhttps.request, curl, wget, or any outbound network calls from the Node/Python\nside. Push delivery is handled entirely by the OpenClaw runtime via stdout/IPC\nprotocol, and is OPT-IN (disabled until the user runs push-toggle.js on).\nThe 'channels' field in user profiles (e.g. telegram) is a routing hint for\nthe OpenClaw runtime, not a direct API integration. This skill does not hold\nor require any third-party API tokens (Telegram Bot Token, SMTP credentials,\nwebhook URLs, etc.). publish.sh is a local-only version management script\nwith no remote upload.\nEXCEPTION — OPTIONAL LLM NETWORK USE: the browser-only file liuyao/index.html\nexposes an optional \"LLM divination\" button. If and only if the user clicks\nit and fills in their own API key + endpoint, the browser (not the skill\nprocess) will POST the hexagram and question to that user-configured endpoint.\nNo key is bundled, hardcoded, or transmitted anywhere else. Users are advised\nto supply a scoped/limited API key rather than a primary account key.\nUser profile data (birth details, optional family members, interaction log)\nis stored only on the local filesystem and can be viewed, edited, or deleted\nat any time via scripts/profile.js (see data-retention.user-controls above).\n"}}} |