whiteguo233/OpenBiliClaw

C2

本地私有、开源的自进化跨平台 AI 内容发现 Agent:先理解你,再主动从 B站、小红书、抖音、YouTube、X、知乎、Reddit、微博等平台与开放 Web 寻找内容。(支持 deepseek harness 插件) | Local-first open-source cross-platform AI content discovery agent: understands you, th

★ 2.9k · whiteguo233/OpenBiliClaw source on GitHub · this plugin in the registry

whiteguo233/OpenBiliClaw is a DeepSeek Harness plugin rated C2 — one powerful capability or sensitive behavior. It executes system commands, reads credential-class env vars.

What it can do

CapabilityFlagEvidence
executes system commandsexec×31 src, e.g. extension/scripts/convert-safari.mjs:1, extension/scripts/convert-safari.mjs:1
reads credential-class env varstoken_envAMO_JWT_SECRET, APPLE_NOTARY_PASSWORD

Outbound domains

www.douyin.com www.reddit.com www.youtube.com www.v2ex.com www.xiaohongshu.com www.bilibili.com www.zhihu.com linux.do x.com bgm.tv

Environment variables it reads

AMO_JWT_ISSUER AMO_JWT_SECRET TARGET APPLE_NOTARY_USER APPLE_NOTARY_PASSWORD APPLE_SIGNING_IDENTITY APPLE_TEAM_ID

How to read this

Levels measure capability surface and transparency, not maliciousness. A C3 plugin can be entirely legitimate — a desktop shell genuinely needs subprocesses. The point is that you can see this before installing. See the levels explained and how dsh plugins work.

Findings come from static analysis of shipped code; nothing is executed. Think a flag is wrong? Open an issue — every flag cites the file and line it came from.