ZappushZappush
SkillsUse CasesBenchmarkCommunitySign In
      Back to Skills
      LANMIN-X

      Safety Report

      ZFONT-CLI

      @LANMIN-X

      从 zfont.cn 智能搜索、推荐并下载免费商用字体,支持递归解压字体包提取 TTF、OTF、TTC 格式文件并提供安装或传输方案。

      66Downloads
      0Installs
      1Stars
      6Versions

      Security Analysis

      high confidence
      Clean0.08 risk

      The skill's declared purpose (searching and downloading fonts from zfont.cn) matches its instructions and requirements; nothing requested is disproportionate, though the agent can autonomously download and handle files so you should trust the remote site and your agent runtime.

      Mar 15, 20261 files2 concerns
      Purpose & Capabilityok

      Name/description, declared required binaries (wget, unzip, cp, bash), and the HTTP endpoints (zfont.cn / files.zfont.cn) all align with a font-search-and-download tool. No unrelated credentials, binaries, or config paths are requested.

      Instruction Scopenote

      Instructions stay within the stated task: search via zfont.cn APIs, fetch a download URL, download to /tmp, optionally unzip and deliver files. They do not request unrelated system files or secrets. Note: get_font_download_url specifies a silent (non-interactive) immediate download when a font ID is obtained, which may cause the agent to fetch archives without an extra explicit user confirmation in some flows.

      Install Mechanismok

      This is an instruction-only skill with no install spec or code to write to disk, which is the lowest-risk install model. All runtime commands are standard system utilities (wget/unzip).

      Credentialsok

      The skill requires no environment variables, no credentials, and no config paths. Network access to zfont.cn/files.zfont.cn is expected and proportional to the purpose.

      Persistence & Privilegenote

      always is false and the skill does not request system-wide changes. However, disable-model-invocation is false (normal), and the skill's logic includes silent download and automated file sending steps—this gives the skill the ability to autonomously fetch and stage binaries (archives) in /tmp and hand them off via the platform's file-send API, increasing blast radius if the remote content is malicious or if agent autonomy is undesired.

      Guidance

      This skill appears coherent for downloading fonts from zfont.cn and doesn't request unrelated secrets. Before installing: 1) Confirm you trust zfont.cn/files.zfont.cn (the skill will download and extract archives from that host). Malicious or malformed font files can still be harmful if opened or installed. 2) Consider disabling autonomous invocation or requiring explicit confirmation for downloads if you want to avoid silent fetches. 3) Run the skill in a sandboxed environment (or review downloaded archives) before installing fonts system-wide. 4) Because the skill's source/homepage is unknown, prefer caution: validate the remote endpoints and test with non-sensitive, disposable environments first.

      Latest Release

      v1.5.3

      zfont-agent-cli 1.5.3 - 优化用户收到字体后的指引:发送文件后,指引内容从代码块样式改为分条说明,更清晰易读 - 发送压缩包或字体文件时,分别用更符合用户习惯的文本格式化说明解压和安装方式 - 其余功能及接口保持不变

      Popular Skills

      self-improving-agent

      @pskoett · 1,456 stars

      Gog

      @steipete · 672 stars

      Tavily Web Search

      @arun-8687 · 620 stars

      Find Skills

      @JimLiuxinghai · 529 stars

      Proactive Agent

      @halthelobster · 426 stars

      Summarize

      @summarize · 415 stars

      Published by @LANMIN-X on ClawHub

      Zappush© 2026 Zappush
      HomeGuaranteeSupport

      Something feels unusual? We want to help: [email protected]