Token导航 LogoToken导航TokenDH.com
开发敏感数据clawhub未标认证来源可访问clear审计通过

auto-skill-evolver自动技能进化器

Agent Skill

auto-skill-evolver 用于补充开发相关能力,适合在 OpenClaw 中需要让 Agent 承接开发相关任务时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

26,349

周安装

1,087

GitHub Stars

2

下载量

8,609
OpenClaw

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

MIT-0

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:auto-skill-evolver(自动技能进化器)
来源仓库:https://github.com/ysshi-fpga/auto-skill-evolver
安装命令:
openclaw skills install auto-skill-evolver
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 OpenClaw 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

ClawHubOpenClaw
openclaw skills install auto-skill-evolver

简介

auto-skill-evolver 是通过追踪+反馈驱动进化的元技能,提升其他技能表现。

  • 适合在 OpenClaw 中需要让 Agent 承接开发相关任务,如技能训练时使用。
  • 目标是让技能训练、状态检查和应用更智能化,提升整体技能水平。
  • 安装命令:openclaw skills install auto-skill-evolver;需确认权限范围和维护状态。
  • 注意是否会触发联网、命令执行或文件读写操作,建议结合原始 README 核验具体用法。

SKILL.md

name
auto-skill-evolver
description
A meta-skill that continuously improves other skills through trace+feedback-driven evolution, with the goal of making skill training, status checking, and approval natural in conversation; optimized for mobile chat routing, it recognizes Chinese/English intents such as 训练技能, 技能迭代, 技能进化, 查看训练状态, train skill, evolve skill, check training status, and approve/apply proposal, then auto-runs propose/status/approve workflows safely.
version
1.5.1
author
Shi Yanshuo
metadata
openclaw
runtime_dependency

Auto Skill Evolver

This skill allows your AI agent to autonomously improve its own skills. It uses an iterative "training" process where the agent practices a task, evaluates the result, and rewrites the skill definition to perform better next time.

⚠️ Security Notice: This skill modifies code/config files on your local machine. It runs the local openclaw CLI and executes arbitrary commands defined by you. Use with caution and review changes before applying them.

Prerequisites

  1. Python 3.8+ installed.
  2. OpenClaw CLI installed and configured (openclaw command available in PATH, external dependency and not bundled by this skill package).
  3. No external API key required (uses your local OpenClaw agent configuration).
  4. Strongly recommended to run with human review (--interactive) unless you are in a trusted CI pipeline.

Usage

1. Self-Training Mode (The "Gym")

Use this mode when you want the agent to practice a specific task repeatedly to perfect a skill.

Command:

python skills/auto-skill-evolver/scripts/train_loop.py \
  --skill-path "skills/target-skill/SKILL.md" \
  --command "[\"your-agent-command\", \"--task\", \"do the thing\"]" \
  --iterations 10 \
  --interval 300 \
  --trace-file "logs/execution.log" \
  --interactive-each-iteration

Parameters:

  • --skill-path: The path to the skill file you want to improve.
  • --command: The command to run the agent task.

- Recommended: pass a JSON array string (e.g., ["bin","--arg","value"]) for exact argv control. - Security hardening: shell operators like &&, |, ;, redirection are rejected to prevent injection.

  • --iterations: How many times to practice (default: 10).
  • --interval: Seconds to wait between iterations (e.g., 1800 for 30 mins).
  • --trace-file: The file where your agent writes its execution logs.
  • --interactive-each-iteration: If enabled, each iteration requires yes or hash approval before apply.

2. In-Process Evolution (Hook Mode)

Use this mode to improve skills during normal usage.

Option A: Command Line Hook

# Step 1: Generate proposal and show full diff in current session
python skills/auto-skill-evolver/scripts/optimize_skill.py \
  --skill-path "skills/target-skill/SKILL.md" \
  --task-desc "User's request" \
  --trace-file "logs/session.log" \
  --feedback-file "logs/user_feedback.txt" \
  --allowed-sections "Usage,How It Works,Security" \
  --interactive

# Step 2: Apply existing proposal later (mobile/remote friendly)
python skills/auto-skill-evolver/scripts/optimize_skill.py \
  --skill-path "skills/target-skill/SKILL.md" \
  --apply-proposal \
  --approval-token yes

# Step 2 (token file mode): avoid exposing token in command args
python skills/auto-skill-evolver/scripts/optimize_skill.py \
  --skill-path "skills/target-skill/SKILL.md" \
  --apply-proposal \
  --approval-token-file "runtime/approval_token.txt" \
  --approval-expire-seconds 1800

# Step 3 (session-first): query current proposal status for mobile chat UI
python skills/auto-skill-evolver/scripts/optimize_skill.py \
  --skill-path "skills/target-skill/SKILL.md" \
  --status \
  --output-mode json

# Step 4 (single-action mobile flow): one action param only
python skills/auto-skill-evolver/scripts/optimize_skill.py \
  --skill-path "skills/target-skill/SKILL.md" \
  --chat-action approve

Option B: Python Integration (Wrapper)

from skills.auto_skill_evolver.scripts.hook_wrapper import trigger_evolution

# After task completion
report = trigger_evolution(
    skill_path="skills/target-skill/SKILL.md",
    task_desc="Analyze financial data",
    trace_file="logs/trace_123.log",
    feedback_file="logs/feedback_123.txt",
    interactive=True  # Ask for yes/hash approval before applying
)
print(report) 

3. Version Control & Rollback

Every time the skill is updated, a backup is saved in .skill_versions/ inside the skill's directory.

Restore a previous version:

from skills.auto_skill_evolver.scripts.version_control import restore_version, list_versions

# List available versions
versions = list_versions("skills/target-skill/SKILL.md")
for v in versions:
    print(v['filename'], v['meta'])

# Restore
restore_version("skills/target-skill/SKILL.md", versions[1]['path'])

How It Works

  1. Execute: The agent runs the task using the current skill.
  2. Evaluate: The execution trace and user feedback are captured.
  3. Optimize: A local OpenClaw sub-agent is spawned to analyze the trace and optimize the skill file.
  4. Rewrite: The sub-agent writes updates using atomic replace to avoid partial writes/corruption.
  5. Report: A changelog is generated (Added/Removed/Impact).
  6. Proposal-First: Proposal artifacts are stored as .proposed and .proposed.meta.json.
  7. Approval: Full unified diff is printed in the same session; apply accepts yes or exact proposal hash.
  8. Deferred Apply: Existing proposal can be applied later with --apply-proposal, no re-optimization needed.
  9. Expiry Guard: Use --approval-expire-seconds to reject stale proposals.
  10. Session Integration: Use --status and --output-mode json to expose proposal state and next actions to chat/mobile UI.
  11. Single-Action Chat Mode: --chat-action propose|status|approve reduces client decision complexity.

Security

This skill includes built-in defenses against Prompt Injection attacks from execution logs and local file tampering:

  1. Prompt Isolation: The optimizer is explicitly instructed to treat logs as untrusted data and ignore any instructions found within them.
  2. Multi-layer Security Scans: Before apply, generated content goes through multiple scanners:

- Diff-aware high-risk behavior detection (new dangerous commands compared with original version) - Absolute high-risk blocklist scan (e.g., curl, rm -rf, chmod 777, disk destructive patterns) - Prompt-injection marker scan (e.g., instruction-override phrases, role-escalation terms)

  1. Permission Validation: Target skill/trace/feedback paths are validated (regular file only, no symlink redirection, required read/write access).
  2. Atomic Writes: Skill proposals, applied updates, and update reports are written atomically (tempfile + os.replace) to prevent partial writes and race-condition corruption.
  3. Local Execution: All optimization happens locally via your configured OpenClaw agent, ensuring no data leaves your controlled environment.
  4. Secure Workspace: Optimization artifacts (traces, logs) are processed in a secured directory (.secure_workspace) with restricted permissions (current user only) to prevent tampering during the update process.
  5. Section Whitelist Rewrite: By default only selected H2 sections are replaceable (Usage, How It Works, Security). Frontmatter and non-whitelisted sections remain unchanged.
  6. Approval Gate: Every proposal has SHA256 fingerprint. Apply accepts yes or exact hash entry, and full diff is always visible in-session.
  7. Token File Approval: --approval-token-file supports file-based approval for mobile/server control without exposing token in process args.
  8. Proposal Expiry: --approval-expire-seconds enforces max age to block stale proposal apply.
  9. Structured Session Output: --output-mode json emits machine-readable proposal/approval events for conversation-driven clients.
  10. Risk Card Field: JSON events include risk_level (low|medium|high) for red/yellow/green mobile cards.
  11. Writable Scope Guard: --allowed-skill-roots limits writable target ranges to approved root paths.
  12. Self-Target Guard: self-modification is blocked by default; use --allow-self-target only in controlled maintenance.
  13. Strict Compatibility Guard: Legacy high-risk flags are rejected with migration guidance.

Mobile Chat Quickstart

Use the same script with one action:

# Start training proposal
python skills/auto-skill-evolver/scripts/optimize_skill.py --skill-path "skills/target-skill/SKILL.md" --chat-action propose --task-desc "..." --trace-file "..." --feedback-file "..."

# Check proposal in 3-line text mode (small screen)
python skills/auto-skill-evolver/scripts/optimize_skill.py --skill-path "skills/target-skill/SKILL.md" --chat-action status --output-mode text

# Approve proposal (requires explicit yes/hash token or interactive input)
python skills/auto-skill-evolver/scripts/optimize_skill.py --skill-path "skills/target-skill/SKILL.md" --chat-action approve

Natural language mode (no need to remember action flags):

# Chinese: start training
python skills/auto-skill-evolver/scripts/optimize_skill.py --chat-text "训练 auto-skill-evolver"

# English: start training
python skills/auto-skill-evolver/scripts/optimize_skill.py --chat-text "train auto-skill-evolver"

# Chinese: check status
python skills/auto-skill-evolver/scripts/optimize_skill.py --chat-text "查看 auto-skill-evolver 状态" --output-mode text

# English: approve
python skills/auto-skill-evolver/scripts/optimize_skill.py --chat-text "approve auto-skill-evolver"

Conversation Triggers

The router can infer action + skill from natural phrases:

  • Chinese training intents: 训练 xxx 优化 xxx 让 xxx 技能迭代 让 xxx 技能进化
  • Chinese status intents: 查看 xxx 训练状态 查询 xxx 状态
  • Chinese approve intents: 批准 xxx 应用 xxx 提案 确认通过 xxx
  • English training intents: train xxx optimize xxx evolve xxx
  • English status intents: status xxx check xxx progress
  • English approve intents: approve xxx apply xxx proposal

If user says 这个技能 / 当前技能 / this skill, it maps to auto-skill-evolver.

Strict Release Profile

This release is hardened for marketplace safety review:

  • No autonomous apply path.
  • No whitelist-bypass flag.
  • Proposal-first workflow is mandatory (.proposed + .proposed.meta.json).
  • Apply requires explicit approval token (yes or proposal hash), including token-file and deferred apply mode.
  • Write scope is constrained by allowed roots and self-target is disabled by default.
  • Recommended to run in isolated development environments.

Legacy high-risk flags are intentionally rejected:

  • --auto-apply
  • --disable-section-whitelist

Security Tests

Run local checks before publishing:

python -m py_compile skills/auto-skill-evolver/scripts/optimize_skill.py
python skills/auto-skill-evolver/scripts/optimize_skill.py --help

Expected outcome:

  • Commands exit with code 0.
  • Legacy high-risk flags are rejected.
  • Whitelist/frontmatter protection works.
  • Hash checks remain stable.

Directory Structure

skills/auto-skill-evolver/
├── SKILL.md              # This file
├── prompts/
│   └── optimizer.md      # The meta-prompt for the Optimizer LLM
└── scripts/
    ├── optimize_skill.py # Core optimization logic
    ├── train_loop.py     # Self-training loop
    └── version_control.py# Backup and restore utilities

适合场景

01

OpenClaw 用户查找和安装 Skill 时

02

用户想查找某类 Agent Skill 时

03

需要根据任务场景推荐可安装能力包时

04

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

补充不同宿主或平台的使用分布数据

能力 5

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

OpenClaw

83.71%
按下载量换算7,207

安全审计

VirusTotal

通过

ClawScan

通过

Static analysis

通过

权限和风险

敏感数据

该 Skill 可能接触密钥、Token、环境变量或敏感配置,应进入高风险复核队列,默认不自动发布。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills