Token导航 LogoToken导航TokenDH.com
开发需要联网clawhub未标认证来源可访问clear审计提醒

email-importance-content-analysis电子邮件重要性内容分析

Agent Skill

用于辅助文档、README、Markdown、说明文和内容稿件的整理与改写。它适合让 Agent 提炼结构、补齐章节、统一术语、检查链接或把零散材料整理成可读文档。使用时应保留项目已有事实、命令和路径,不要把未确认的信息写成确定结论;涉及对外文案时,还需要控制语气,避免过度营销或夸大能力。

总安装

33,936

周安装

1,414

GitHub Stars

公开资料未说明

下载量

11,312
OpenClaw

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

MIT-0

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:email-importance-content-analysis(电子邮件重要性内容分析)
来源仓库:https://github.com/shingo0620/email-importance-content-analysis
安装命令:
openclaw skills install email-importance-content-analysis
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 OpenClaw 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

ClawHubOpenClaw
openclaw skills install email-importance-content-analysis

简介

使用基于内容的分析而不是发件人姓名或邮箱标签(可能是欺骗性的)来判断电子邮件是否重要/紧急。当被要求对电子邮件进行分类、决定优先级、检测网络钓鱼/社交工程或根据消息要求用户执行的操作推荐下一步操作(回复/支付/登录/下载/点击)时使用。

SKILL.md

name
email-importance-content-analysis
description
Judge whether an email is important/urgent using content-based analysis rather than sender name or mailbox labels (which can be spoofed). Use when asked to triage emails, decide priority, detect phishing/social-engineering, or recommend next actions (reply/pay/login/download/click) based on what the message asks the user to do.

Email Importance Content Analysis

Use a subject/title-first triage, then perform technical verification (headers/links/attachments) only when warranted, and only then validate with content analysis. Treat sender display name, badges, labels, and “From” appearance as untrusted.

Workflow (title → technical → content)

1) Title/subject + sender triage (cheap first-pass)

Use only: subject line + sender (display name + email address/domain as shown). Do not click anything.

Important: treat sender as weak signal (can be spoofed). Use it for triage only.

1A) Fast-drop rules (save time)

If the sender looks obviously sloppy/spoofed AND the email is not expected, classify as Likely scam/ads and stop (do not spend time on technical verification). Examples of fast-drop signals:

  • Display name claims a bank/government/major brand but the address is from a free mailbox (gmail/outlook/163/qq) or unrelated domain
  • Lookalike domains / typo-squatting: paypaI (I/l), micros0ft (0/O), extra -secure/-verify, weird punctuation
  • Suspicious TLDs or brand stuffed into subdomain: brand.security-check.example.com
  • Very unprofessional local-part patterns (random digits/strings) while claiming official identity
  • Pure promo patterns (promo/marketing/news) + obvious sales subject ⇒ treat as ads

1B) Escalate rules (to technical verification)

Escalate for technical verification if subject OR sender implies any of:

  • Money/settlement: 扣款/圈存/付款/退款/發票/帳單/對帳單/繳費
  • Account/security: 登入/驗證/密碼重設/異常登入/停權/封鎖/安全警告
  • Delivery/download: 文件下載/取件號碼/包裹/物流失敗
  • Urgency/threat: 最後通知/24小時內/立即/否則將…
  • Execution: 附件/請下載/請開啟/啟用巨集

If the subject is clearly marketing/newsletter and no action is implied ⇒ usually stop here (Low).

If it triggers the fast-drop rules, you may label it as:

  • Importance: Low
  • Risk: Medium–High (spoof attempt)
  • Next step: Do not click; optionally mark as spam/block

2) Technical verification (only for emails that passed title triage)

Prefer evaluating raw email headers / “Show original” output (or via gog gmail get). Check:

  • Authentication-Results: SPF / DKIM / DMARC results (pass|fail|neutral) and note which domain they authenticate
  • Alignment: whether DKIM d= domain / SPF MAIL FROM / DMARC aligns with the visible From domain
  • From vs Reply-To mismatch
  • Links and attachments:

- Expand the real target domain (hover/copy link) — don’t trust anchor text - Note risky attachments (e.g., .zip, .iso, .js, .vbs, .docm, password-protected archives)

If headers are not available, mark Technical verdict = Unknown and increase caution.

3) Extract the actionable claims (facts only) — only if technical verification passes

From the email body, list:

  • What happened / what they claim happened
  • What they want the recipient to do (and by when)
  • What account/system/money is involved
  • What evidence they provide (order id, invoice id, ticket id, last-4 digits, timestamps)

4) Classify the required action (drives importance)

Rank higher if it requires any of:

  • Account access / authentication: login, password reset, 2FA codes, device approval
  • Money movement: payment, wire, subscription renewal, invoice settlement, refunds
  • Permissions / security posture: granting access, changing roles, API keys, OAuth consent
  • Software execution: download/open an attachment, run a file, enable macros
  • Data disclosure: personal/company info, documents, ID numbers

5) Content risk patterns (red flags)

Increase risk if the content shows:

  • Urgency / threat: “within 24h”, “account will be closed”, “legal action”, “final notice”
  • Secrecy / bypass: “don’t tell others”, “use personal email”, “avoid normal process”
  • Mismatch / vagueness: generic greeting, unclear context, missing specifics the real sender would know
  • Odd requests: asking for OTP, gift cards, crypto, remote access, or direct bank changes
  • Link/attachment pressure: “click to verify”, “download to view”, “enable macros”

6) Choose safe verification (do not trust the email path)

Even if SPF/DKIM/DMARC pass, for sensitive actions recommend out-of-band verification:

  • Navigate via known official entry points (typed URL, app, bookmark), not email links
  • If it claims an account issue: check account status by logging in from official site/app
  • If it’s a vendor/payment issue: verify using the invoice/order id inside the official portal
  • If it’s workplace related: verify via internal chat/phone using known contacts

7) Output: priority + next action

Always provide:

  • Title triage verdict: Escalate / Ignore
  • Technical verdict: Pass / Fail / Unknown
  • Importance level: Critical / High / Medium / Low
  • Risk level: High (likely phishing) / Medium / Low
  • Recommended next step: what to do *now*, what *not* to do, and how to verify

Decision Heuristics (quick)

  • Technical FAIL (SPF/DKIM/DMARC fail or obvious mismatch) + any call-to-action ⇒ Risk: High (treat as phishing) regardless of “importance”.
  • Critical: money/credentials/permissions + urgency OR any request for OTP/macro/remote access.
  • High: requires action soon, could cause loss of access/service interruption, but can be verified safely via official channels.
  • Medium: informational but relevant; no immediate sensitive action.
  • Low: newsletters, marketing, generic updates with no action.

Response Template (use in replies)

  • Title triage (why it escalates / why it can be ignored):
  • Technical verification (SPF/DKIM/DMARC + alignment + From/Reply-To + link/attachment notes):
  • Summary (1–2 lines):
  • What it’s asking you to do:
  • Why it may matter (impact if ignored):
  • Red flags (if any):
  • Safe verification path:
  • Recommendation (do / don’t):

适合场景

01

OpenClaw 用户查找和安装 Skill 时

02

用户想查找某类 Agent Skill 时

03

需要根据任务场景推荐可安装能力包时

04

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

补充不同宿主或平台的使用分布数据

能力 5

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

OpenClaw

72.37%
按下载量换算8,186

安全审计

VirusTotal

可疑

ClawScan

通过

Static analysis

未展示

权限和风险

需要联网

该 Skill 可能需要联网访问来源站点、仓库或外部 API;具体网络访问范围需要结合源码和 README 复核。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。来源安全扫描存在 warning/failed 结果,不能写成本站确认安全。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills