openclaw-rss-feedsRSS/Atom feed digest with optional CVE enrichment, Ghost CMS drafts, and channel notifications
Install via ClawdBot CLI:
clawdbot install homeofe/openclaw-rss-feedsGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Sends data to undocumented external endpoint (potential exfiltration)
post → https://blog.example.com/p/ghost-post-1/Calls external URL not in known-safe list
https://www.fortiguard.com/rss/ir.xmlAI Analysis
The skill's external calls are to explicitly configured, legitimate RSS feeds and a user-specified Ghost CMS instance for publishing, which aligns with its stated purpose. No credential harvesting, hidden instructions, or obfuscation is present. The 'UNKNOWN_DATA_SINK' signal is a false positive, as the destination is the user's own configured blog.
Audited Apr 17, 2026 · audit v1.0
Generated Mar 1, 2026
A security operations center (SOC) uses this plugin to automatically aggregate RSS feeds from vendors like Fortinet and Microsoft, enriching CVEs with NVD data to prioritize vulnerabilities above a CVSS threshold. The digest is published as a Ghost CMS draft for internal review and notifications are sent via WhatsApp or Telegram to alert team leads. This streamlines weekly or monthly threat briefings without manual data collection.
A government agency, such as BSI CERT-Bund, configures the plugin to monitor security advisories from multiple sources, filtering for critical keywords like 'kritisch' or 'CVE'. It runs on a scheduled basis to generate compliance reports, with digests saved as Ghost drafts for audit trails and notifications sent to compliance officers via secure channels. This ensures timely awareness of regulatory updates and vulnerabilities.
An MSSP sets up the plugin for multiple client feeds, using keywords and CVE enrichment to customize digests per client based on their infrastructure (e.g., Fortinet devices). Digests are automatically created as Ghost drafts for client portals, and summary notifications are pushed to Discord channels for each client's security team. This automates recurring reporting and enhances client engagement.
A university research team uses the plugin to aggregate feeds from sources like Heise Security, enabling CVE enrichment to analyze vulnerability trends over time. The digest is published as a Ghost draft for collaborative editing and sharing within the research group, with notifications sent to team members via Telegram for new findings. This supports data-driven studies without manual feed parsing.
A software development company configures the plugin to monitor RSS feeds for security updates related to their tech stack, such as Microsoft 365 or open-source tools. CVE enrichment filters high-severity issues, and digests are published as Ghost drafts for developer review, with WhatsApp notifications to engineering leads. This integrates security awareness into the development lifecycle proactively.
Offer this plugin as part of a cloud service where organizations pay a monthly fee for automated RSS digest generation, CVE enrichment, and notifications. Revenue comes from tiered subscriptions based on the number of feeds, users, or advanced features like custom integrations. This model targets small to medium-sized businesses lacking in-house development resources.
Provide consulting services to help enterprises install, configure, and customize the plugin for their specific needs, such as integrating with existing Ghost CMS instances or adding new notification channels. Revenue is generated through project-based fees or ongoing support contracts. This model appeals to large organizations with complex security workflows.
Distribute the plugin as open-source with basic functionality free to use, while charging for premium features like advanced CVE enrichment, higher rate limits, or exclusive notification channels. Revenue streams include one-time purchases for add-ons or enterprise licenses. This model attracts a broad user base while monetizing advanced capabilities.
💬 Integration Tip
Ensure your Ghost CMS instance is properly configured with an admin API key in the correct format, and test notifications with a dry run before full deployment to avoid disruptions.
Scored Apr 19, 2026
Monitor blogs and RSS/Atom feeds for updates using the blogwatcher CLI.
Fetch top news from Baidu, Google, and other sources daily.
多源 AI 科技新闻简报聚合器。覆盖 AI 大模型、科技、财经,按热度分级输出,来源全程可溯。AIHOT 168 信源并行覆盖。8 维度强制搜索,15-20 条精选内容。支持 Twitter/X 和 Grok API。
查询并分析Google Trends在指定时间范围和国家/地区的实时热门话题与热搜。当用户提到谷歌趋势、热门话题、实时热搜、流行趋势、当前热点、近期热门、病毒式话题、时间段热度、区域趋势分析、Google Trends, real-time hot topics, trending topics, popular...
Turn scattered notes, chat logs, meeting fragments, issue updates, or calendar context into a concise daily brief. Use when Codex needs to summarize what hap...
提供全球量子计算领域最新中文资讯聚合,包括技术突破、企业动态、融资信息及发展路线图分析。