Atlas / Skills / worldwonderer / Story Setup

Story SetupCAUTION

skills/worldwonderer/story-setup

Claude Code / Codex / OpenCode agent skills for writing Chinese web novels (网文): 扫榜、拆文、写作、去AI味、封面全流程,长篇短篇都支持 | 13 skills for novel writing and long-form fiction with file-based continuity tracking. MIT.

Verdict
CAUTION
Grade
B
Trust score
89 /100
Version
1.3.2
Hosts
3 documented
License
MIT
Stars
7,365
01

Overview

Claude Code / Codex / OpenCode agent skills for writing Chinese web novels (网文): 扫榜、拆文、写作、去AI味、封面全流程,长篇短篇都支持 | 13 skills for novel writing and long-form fiction with file-based continuity tracking. MIT.

Read from source at commit 2ad3dba961bdOBSERVED · 2026-10-08
02

Install

Commands as the repository documents them. They are shown, not run.

claude plugin install oh-story@oh-story-skills --scope user
03

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
claude-codementioned
codexmentioned
openclawmentioned
04

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: story-setup
version: 1.3.2
description: "网文写作工具集基础设施部署与检查。为 Claude Code / OpenCode / Codex / Google Antigravity / ZCode / OpenClaw / Reasonix 提供内置适配;Web AI / 通用 Agent 可走 skills + AGENTS.md 文件模式。触发方式:/story-setup、$story-setup、「准备写书」「帮我搭一下环境」「配置写作项目」「检查写作环境」。"
metadata: {"openclaw":{"source":"https://github.com/zenstory-ai/oh-story-claudecode"}}
---
# story-setup:网文写作工具集基础设施部署

你是写作基础设施部署器。将网文写作工具集部署到用户项目目录:已适配的 CLI 走专用 hooks/agents/config;NarraFork、Web AI、自定义 Agent 等环境走通用文件模式。

**执行铁律:不覆盖用户已有配置,合并而非替换。**

作者第一次部署的顺序:判断当前宿主 → 确认项目根 → 按宿主部署 → 验收 → 告诉作者下一步。本文件只写各宿主通用的流程;每个宿主专属的部署清单、算法、校验和安装报告提示在各自的部署文件里,**只读本次目标宿主的那一份**(见 Phase 2)。

## 选择模式

- 参数为 `check`,或用户只要求检查部署、诊断环境、排查 agent 不可用时:完整读取 [references/diagnostics.md](references/diagnostics.md),按其中流程仅检查并报告;不进入下面的部署流程。
- 用户要求安装、更新或修复时:执行下面的部署流程。检查后已明确授权的修复沿用本文件与宿主部署文件的部署与合并规则。

---

## Phase 1:判断宿主与项目

**先自检参考目录**:以正在执行的本 `SKILL.md` 所在目录为准,列出与它同级的 `references/` 下的子目录,核对下面 9 个名字是否都在**且都非空**——`agent-references`、`templates`、`opencode`、`codex`、`antigravity`、`zcode`、`openclaw`、`reasonix`、`generic`;同级 `references/deploy-*.md`(8 份宿主部署文件)、`scripts/merge-claude-settings.py`、`scripts/merge-codex-hooks.py`、`scripts/merge-antigravity-hooks.py`、`scripts/generate-antigravity-agents.mjs`、`scripts/deploy-antigravity-skills.py` 与 `scripts/copy-path-safety.py` 也必须存在(宿主部署步骤、Claude/Codex/Antigravity hooks 合并、Antigravity Skills 物化与 agent 生成、递归复制安全检查依赖它们)。有缺即 skill 包没装全,**立即停止,不写任何部署文件**,报告里区分「缺目录」「目录为空」和「缺脚本或部署文件」,并给修复指令:「story-setup 参考资料包不完整,缺 {路径}。按你的安装方式重装 oh-story-claudecode(命令行装的重跑 `npx skills add zenstory-ai/oh-story-claudecode -y -g`,marketplace / Plugin Management 装的在面板里重装),再执行 /story-setup。」

> 判据是「有没有 `SKILL.md`」:只看正在执行的 `SKILL.md` 同级的 `references/`。项目内 `.claude/skills/story-setup/`、`.codex/skills/story-setup/` 和 OpenCode 的 `skills/story-setup/` 只有 `references/agent-references/`、不含 `SKILL.md`,不会是执行目录,也不要拿它们核对。Antigravity / ZCode / OpenClaw / Reasonix / generic 的项目副本是整份 skill 拷贝、自带 `SKILL.md`,9 个子目录本就齐全,照常核对即可。

1. 检查当前目录是否已部署过(存在 `.story-deployed`)
   - `agents_version` 缺失、非整数或小于 `34` → 标记为待更新,继续执行当前部署
   - `agents_version: 34` → 使用 AskUserQuestion 确认是否重新部署;提示里写明重新部署只用**当前本地 skill 包**刷新项目文件,要拿 skill 本身的新版本得先更新 oh-story-claudecode(`npx skills add` 或 marketplace),再回来重跑
   - `agents_version` 大于 `34` → 当前 story-setup 比项目部署旧;停止以避免降级覆盖,提示先更新 oh-story-claudecode,不写任何部署文件
   - 同时读 `target_cli` 字段。**已部署项目以 sentinel 里的值为准**:非空时(逗号分隔的多端组合原样保留)这些端照常重新部署,不再让作者选;第 4 步仍判断当前宿主:判断出来且不在其中(作者换了软件)→ AskUserQuestion 问「这个文件夹之前是给 {已部署宿主名} 装的,你现在用的是 {当前宿主名},要一起装上吗?」(「一起装上(推荐)」「只更新原来的」),选前者就加进 `target_cli`;判断不出不问。字段缺失或为空才走第 4-6 步。用户明确要求增删目标端时,用 AskUserQuestion 在现有值基础上改,改完的值写回 sentinel。
   - `target_cli` 不含 opencode、但项目里有 `.opencode/plugins/story-hooks.ts` 或 `.opencode/agents/`(多端部署时 OpenCode 曾被版本门拦下)→ 用 AskUserQuestion 问是否把 OpenCode 加回来;选加回则先过 [references/deploy-opencode.md](references/deploy-opencode.md) 的「部署前置」,通过后写回 `target_cli`
2. 检查是否有书名目录(包含 `追踪/` 子目录的目录,或用户自定义结构)
   - 有 → 识别为长篇项目,显示当前项目信息
   - 无 → 识别为新项目或短篇项目
3. 检查 `.active-book` 文件是否存在:存在 → 显示当前活跃书目;不存在 → 跳过
4. **判断当前宿主(能判断就不问作者)**。依次看,第一条能定下来的就用:
   - 你自身的运行环境:系统提示、可用工具名或 skill 调用语法已表明你运行在 Claude Code、Codex、OpenCode、Google Antigravity(含命令行 `agy`)、ZCode、OpenClaw 或 Reasonix 里;
   - 正在执行的本 `SKILL.md` 的安装位置带有宿主专属目录(如 `.claude/`、`.codex/`、`.zcode/`、`.gemini/`、`.openclaw/`、`.opencode/`);
   - 判断不出(例如网页版 AI、自建 Agent,或以上信号互相矛盾)→ 第 5 步的项目标记只当候选,交第 6 步问作者。
5. 看项目里已有哪些宿主的标记:
   - `.claude/` 或 `CLAUDE.md` → `target_cli = claude-code`
   - `opencode.json`、`opencode.jsonc` 或 `.opencode/` → `target_cli = opencode`
   - `.codex/`、`.codex/config.toml`、`.codex/agents/`、`.codex/hooks.json`、`AGENTS.md` 中的 Codex 段 → `target_cli = codex`
   - `.agents/hooks.json`、`.agents/agents/`,或 `.agents/rules/oh-story.md` 中的 Antigravity 标记 → `target_cli = antigravity`
   - `.zcode/`、`.zcode/config.json`、`zcode.json`、`.zcode/skills/`、`.zcode/commands/`、`AGENTS.md` 中的 ZCode 段 → `target_cli = zcode`
   - `openclaw.json`、`.openclaw/`,或 `AGENTS.md` 中的 OpenClaw 段(标题行含 `网文写作工具集(OpenClaw)`)→ `target_cli = openclaw`
   - `.reasonix/`、`reasonix-plugin.json`、`REASONIX.md`,或 `AGENTS.md` 中的 Reasonix 段(标题行含 `网文写作工具集(Reasonix)`)→ `target_cli = reasonix`
   - `AGENTS.md` 中的通用段(标题行含 `网文写作工具集(通用 Agent / Web AI)`)→ `target_cli = generic`

   > 后三类只认各端**互斥**的标记:`skills/*/SKILL.md` 的 `metadata.openclaw` 不作 OpenClaw 信号(13 个 skill 都带,三条 skills-only 路径部署出的 `skills/` 一样);`.agents/skills/` 由 Antigravity、Codex 与 Reasonix 共用,也不单独作准。
6. 定下 `target_cli`:
   - 第 4 步定出了当前宿主 → `target_cli` 就是它。项目里另有其他宿主的标记时,用 AskUserQuestion 问一句白话:「这个文件夹之前也给 {其他宿主名} 装过写作工具,这次要一起更新吗?」选项:「只装 {当前宿主名}(推荐)」「一起更新」。作者一开始就说要装多个时照办。
   - 定不出、项目标记恰好只有一个宿主 → AskUserQuestion 问「上次是给 {宿主名} 装的,这次还是它吗?」,是就用它,不是按下一条问。
   - 定不出、其余情况 → 用 AskUserQuestion 问:「你现在是在哪个软件里跟我对话?」选项用产品名加一句说明:Claude Code(Anthropic 的命令行 / 桌面版)、Codex(OpenAI 的命令行)、OpenCode、Google Antigravity(含命令行 agy)、ZCode、OpenClaw、Reasonix(DeepSeek 的命令行)、网页版 AI 或其他工具(NarraFork、自建 Agent 等)、好几个都要用。提问工具一次放不下这么多选项时,把项目标记里出现过的放前面,其余让作者在「其他」里直接写名字。
   - 作者的答案按「Claude Code → `claude-code`、网页版 AI 或其他工具 → `generic`、其余取小写产品名」换成 `target_cli`;多端为 `claude-code,opencode,codex,antigravity,zcode,openclaw,reasonix,generic` 中选中的端。
7. **确认项目根(通常不问)**:项目根就是当前工作目录。只有当前目录是用户主目录、磁盘根目录、系统目录,或就是本 skill 包自身的安装/源码目录时,才用一句白话问作者:「写作工具要装在哪个文件夹?一般就是放书稿的那个文件夹。」其他情况直接部署,在安装报告的「部署明细」里写明装在哪。

## Phase 2:部署基础设施

整个 Phase 2 幂等:目录复制、文件写入和各宿主部署文件里的合并算法重复执行结果一致。因环境原因(工具不可用、权限被拒、网络失败)中途失败时,直接从头重跑本 Phase,不需要先清理半成品;`create only if absent` 的用户状态文件(见各部署清单的 Owner class)不会被二次覆盖。

**两列基准目录不同**:部署清单里 `Source path` 相对正在执行的这份 skill 包,`Target path` 相对用户项目根。执行每一行(以及各宿主部署算法里的每个递归复制步骤)之前,先把通配符具体化为单个源/目标,再用本 `SKILL.md` 同级的 `scripts/copy-path-safety.py` 检查。该脚本按 `Path.resolve` / `realpath` 语义跟随已有 symlink,并在两侧都存在时用 `samefile` 核对文件系统对象;**只转绝对路径或比较字符串不算检查完成**。读取其 JSON:`status: same` 时 no-op,禁止复制;仅 `copy_allowed: true` 时可以复制;`source_missing`、`unsafe_target_within_source` 或 `filesystem_identity_error` 必须停止该步骤并报告。无法运行脚本时只能用当前环境的文件系统 API 做完全相同的 canonical realpath、same-object 与 target-descendant 检查;无法确认就停止,不得尝试复制。OpenC
05

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
UNDECLARED (5 observation(s))
Network
declared (2 observation(s))
Shell
declared (5 observation(s))
Dependencies
pinned
Secrets in source
none-found

Findings (8)

MEDIUMInventory / provenance · inv.symlink · CWE-1104
.agents/skills
.agents/skills
Why it matters. link not followed
MEDIUMFilesystem / path · fs.destructive · CWE-22, CWE-59
scripts/deploy-antigravity-skills.py:88
shutil.rmtree(target)
MEDIUMFilesystem / path · fs.destructive · CWE-22, CWE-59
scripts/deploy-antigravity-skills.py:102
shutil.rmtree(backup)
MEDIUMFilesystem / path · fs.destructive · CWE-22, CWE-59
scripts/deploy-antigravity-skills.py:113
shutil.rmtree(staging)
MEDIUMFilesystem / path · fs.destructive · CWE-22, CWE-59
scripts/deploy-antigravity-skills.py:115
shutil.rmtree(backup)
MEDIUMFilesystem / path · fs.destructive · CWE-22, CWE-59
scripts/generate-antigravity-agents.mjs:203
fs.rmSync(target, { recursive: true, force: true })
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
UPGRADING.md:69
1. 升级 OpenCode:先卸载旧包 `npm rm -g opencode-ai`,再 `npm i -g @opencode/cli`(或 `curl -fsSL https://opencode.ai/v2/install | bash`),确认 `opencode --version` 为 2.x。两个包都提供 `opencode` 命令,不先卸载旧包时 PATH 上可能仍是 1.x。
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
references/deploy-opencode.md:11
- 主版本 < 2 → 停止 OpenCode 部署(其它 target 照常),告诉用户先升级到 2.x(先 `npm rm -g opencode-ai`,再 `npm i -g @opencode/cli` 或 `curl -fsSL https://opencode.ai/v2/install | bash`),装好后重跑 story-setup

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 2ad3dba961bdfull audit observations/trust-audit/skill/worldwonderer__story-setup.json · Report an issue / request a re-scan
06

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-082ad3dba961bdCAUTIONB89first audit
07

Questions

What does the Story Setup skill do?

Claude Code / Codex / OpenCode agent skills for writing Chinese web novels (网文): 扫榜、拆文、写作、去AI味、封面全流程,长篇短篇都支持 | 13 skills for novel writing and long-form fiction with file-based continuity tracking. MIT.

Is Story Setup safe to install?

With care. The audit graded it B (89/100) and found 8 things worth knowing before you trust this skill, listed below with the exact line each was found on.

What can Story Setup access on my machine?

The audit observed that it reaches the network, runs shell commands and reads or writes files. At least one of those is not mentioned in its own description, which is itself a finding. Secrets in the source: none found.

Which assistants does Story Setup work with?

Its documentation mentions claude-code, codex and openclaw. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (2ad3dba961bd), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement