用户咨询腾讯云产品资源、AWS、阿里云等多云资源时,查看智能顾问架构图、架构目录、架构详情、架构评估结果、绘制架构图、开通智能顾问时、AI智能巡检、AI容量监测、AI混沌演练、AI云诊断、主动预警、架构健康度、云运维问答、云资源查询、云成本优化、安全合规、云资源盘点、闲置资源检查、云产品最佳实践等AIOps、ChatOps、CloudOps操作时使用。

MITAuto-check passed

Install Cloudq

skills CLI
$ npx skills add LeoYeAI/openclaw-master-skills --skill cloudq -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install LeoYeAI/openclaw-master-skills cloudq --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cloudq .claude/skills/cloudq && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cloudq
GitHub stars
2.2k
Used in
1 other repo
Token cost
~3.9k tokens
SKILL.md length
792 words
Files
19 (incl. scripts, references)
Skills in repo
972
Repo updated
First seen
Licence
MIT

At a glance

用户咨询腾讯云产品资源、AWS、阿里云等多云资源时,查看智能顾问架构图、架构目录、架构详情、架构评估结果、绘制架构图、开通智能顾问时、AI智能巡检、AI容量监测、AI混沌演练、AI云诊断、主动预警、架构健康度、云运维问答、云资源查询、云成本优化、安全合规、云资源盘点、闲置资源检查、云产品最佳实践等AIOps、ChatOps、CloudOps操作时使用。

  • Works in 4 steps: 将创建 CAM 角色 advisor,仅用于免密登录控制台查看智能顾问信息 → 将关联策略… → 信任策略仅允许当前账号扮演此角色 → …
  • SKILL.md covers 零、自我介绍, 一、鉴权方式, 二、前置检查(初始化工作流) and 三、API 调用方式, plus 4 more sections
  • Runs Python and Shell scripts from its folder; calls python3; reaches console.cloud.tencent.com and cloud.tencent.com; needs TENCENTCLOUD_SECRET_KEY and TENCENTCLOUD_TOKEN

What it does

Cloudq is an agent skill from LeoYeAI/openclaw-master-skills. 用户咨询腾讯云产品资源、AWS、阿里云等多云资源时,查看智能顾问架构图、架构目录、架构详情、架构评估结果、绘制架构图、开通智能顾问时、AI智能巡检、AI容量监测、AI混沌演练、AI云诊断、主动预警、架构健康度、云运维问答、云资源查询、云成本优化、安全合规、云资源盘点、闲置资源检查、云产品最佳实践等AIOps、ChatOps、CloudOps操作时使用。

Its SKILL.md is about 3.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 21 other files, including scripts and reference files (for example `EXPERT.md`, `_meta.json` and `archive.sh`).

It works with Amazon Web Services and Tencent Cloud. The repository describes itself as: 🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai. The licence is MIT.

Example prompts

  • “/cloudq”

Requirements

  • Python 3
  • A Bash shell
  • A credential in TENCENTCLOUD_SECRET_KEY
  • A credential in TENCENTCLOUD_TOKEN
  • Pre-approved tools (allowed-tools): execute_command, read_file

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. 将创建 CAM 角色 advisor,仅用于免密登录控制台查看智能顾问信息
  2. 将关联策略 QcloudAdvisorFullAccess(智能顾问只读访问权限,不影响其他云资源)
  3. 信任策略仅允许当前账号扮演此角色
  4. 用户可随时在 CAM 控制台删除此角色

What it can do on your machine

Read from SKILL.md and the folder at commit e5199b5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • execute_command
    • read_file

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 5 files in scripts/ (Python and Shell, from the files we listed), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • console.cloud.tencent.com
    • cloud.tencent.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • TENCENTCLOUD_SECRET_KEY
    • TENCENTCLOUD_TOKEN
    • SECRET_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cloudq loads about 3.9k tokens when it runs, and up to ~8k if it reads all its reference files. Until then it costs about 46 tokens; SKILL.md has 792 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~46
When it runs · the whole SKILL.md, loaded when a task matches
~3.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from LeoYeAI/openclaw-master-skills at commit e5199b5, republished under its MIT licence (© LeoYeAI). 792 words, ~3,859 tokens.

Download SKILL.mdSave it as .claude/skills/cloudq/SKILL.md (or your agent's skills folder). This skill also uses 18 other files; get the full folder from GitHub.
name
cloudq
description
用户咨询腾讯云产品资源、AWS、阿里云等多云资源时,查看智能顾问架构图、架构目录、架构详情、架构评估结果、绘制架构图、开通智能顾问时、AI智能巡检、AI容量监测、AI混沌演练、AI云诊断、主动预警、架构健康度、云运维问答、云资源查询、云成本优化、安全合规、云资源盘点、闲置资源检查、云产品最佳实践等AIOps、ChatOps、CloudOps操作时使用。
allowed-tools
execute_command, read_file

🦞 CloudQ — 全球首款 ITOM "领域虾"

零、自我介绍

当用户询问"你是谁"、"cloudq 是什么"、"cloudq 能做什么"、"介绍一下自己"等身份相关问题时,必须使用以下内容回答(保持 emoji 和格式):

Hi,我是 CloudQ — 全球首款 ITOM "领域虾"

我能帮您: 🦞全渠道 ChatOps,随时随地管好云 既能在 WorkBuddy、Qclaw、LightClaw 等中使用,也能直连微信、企微、QQ、飞书、钉钉、Slack 等 IM;

🤖全天候 AIOps,从被动响应到主动决策 依托「腾讯云智能顾问 TSA」的架构可视化+治理智能化,实现卓越架构治理新范式;

☁️全方位 CloudOps,一只龙虾即可管理多云 统一纳管腾讯云、阿里云、AWS、Azure、GCP 等主流云服务; (相关能力陆续开放中,详情请见:https://cloud.tencent.com/developer/article/2645159)

CloudQ: Just Q IT!


核心能力:通过 AK/SK 鉴权调用腾讯云智能顾问(Tencent Cloud Smart Advisor)API,管理云架构图的目录与详情、获取架构评估结果,以及查询风险评估项。


一、鉴权方式

使用腾讯云 API AK/SK 签名认证(TC3-HMAC-SHA256),通过环境变量配置密钥:

1.1 必填环境变量
  • TENCENTCLOUD_SECRET_ID — 腾讯云 SecretId(必填)
  • TENCENTCLOUD_SECRET_KEY — 腾讯云 SecretKey(必填)

密钥获取地址:https://console.cloud.tencent.com/cam/capi

安全建议:

  • 推荐使用子账号密钥,仅授予 QcloudAdvisorFullAccess 权限,避免使用主账号密钥
  • 生产环境推荐使用临时密钥(STS Token),设置 TENCENTCLOUD_TOKEN 环境变量
  • 通过 export 设置当前会话环境变量即可,无需写入 shell 配置文件

设置当前会话环境变量:

bash
export TENCENTCLOUD_SECRET_ID="your-secret-id"
export TENCENTCLOUD_SECRET_KEY="your-secret-key"

如需跨会话持久化,可写入 shell 配置文件(注意保护文件权限):

bash
echo 'export TENCENTCLOUD_SECRET_ID="your-secret-id"' >> ~/.zshrc
echo 'export TENCENTCLOUD_SECRET_KEY="your-secret-key"' >> ~/.zshrc
source ~/.zshrc
1.2 角色配置(免密登录需要)

为生成控制台免密登录链接,需要配置 CAM 角色。角色配置分为 检测 和 创建 两个独立步骤,角色创建属于 IAM 写入操作,必须在用户明确同意后才能执行。

步骤一:环境检测(只读)

运行环境自检脚本,检测依赖、版本更新、密钥、角色配置状态:

bash
python3 {baseDir}/check_env.py

自检脚本 仅做只读检测,不会创建或修改任何资源。返回码含义:

  • 0 = 环境就绪(密钥 + 角色全部正常)
  • 1 = Python 版本不满足要求
  • 2 = AK/SK 未配置或无效
  • 3 = 角色未配置(需要执行步骤二)

脚本首次运行时会自动检查本地 _meta.json 中的版本号与远端最新版本是否一致。若发现新版本,会输出 changelog(变更日志)并提示用户是否更新,但不会阻断流程,当前版本仍可正常使用。可通过 --skip-update 参数跳过版本检查。

步骤二:角色创建(需用户同意)

当 check_env.py 返回码为 3(角色未配置)时,必须向用户展示角色创建方案并等待同意:

向用户说明以下内容:

  1. 将创建 CAM 角色 advisor,仅用于免密登录控制台查看智能顾问信息
  2. 将关联策略 QcloudAdvisorFullAccess(智能顾问只读访问权限,不影响其他云资源)
  3. 信任策略仅允许当前账号扮演此角色
  4. 用户可随时在 CAM 控制台删除此角色

用户同意后,执行角色创建脚本:

bash
python3 {baseDir}/scripts/create_role.py

脚本输出 JSON 格式结果,success: true 表示创建成功并已保存配置。

用户拒绝时,提供手动配置方式(方式二、三、四)。

方式二:配置向导(交互式选择已有角色)

运行配置向导,从已有角色中选择,或交互式创建新角色:

bash
python3 {baseDir}/scripts/setup_role.py
方式三:简化配置

只需提供角色名称,系统自动获取账号 UIN。将以下内容写入 shell 配置文件(如 ~/.bashrc 或 ~/.zshrc):

bash
echo 'export TENCENTCLOUD_ROLE_NAME="advisor"' >> ~/.bashrc
source ~/.bashrc

系统会自动调用 API 获取您的账号 UIN,并拼接完整的 roleArn。

方式四:完整配置(高级用户)

手动设置完整的角色 ARN,写入 shell 配置文件(如 ~/.bashrc 或 ~/.zshrc):

bash
echo 'export TENCENTCLOUD_ROLE_ARN="qcs::cam::uin/100001234567:roleName/advisor"' >> ~/.bashrc
source ~/.bashrc
1.3 可选环境变量
  • TENCENTCLOUD_TOKEN — 临时密钥 Token(使用临时密钥时设置)
  • TENCENTCLOUD_ROLE_SESSION — 角色会话名称(默认 advisor-session)
  • TENCENTCLOUD_STS_DURATION — 临时凭证有效期秒数(默认 3600,即 1 小时;最大 43200,即 12 小时)

注意:所有环境变量均需永久写入 shell 配置文件(如 ~/.bashrc、~/.zshrc),export 仅对当前会话生效,新开会话会丢失。

1.4 配置优先级

系统按以下优先级加载角色配置:

  1. 环境变量 TENCENTCLOUD_ROLE_ARN(完整 ARN)
  2. 配置文件 ~/.tencent-cloudq/config.json
  3. 环境变量 TENCENTCLOUD_ROLE_NAME + 自动获取账号 UIN

二、前置检查(初始化工作流)

每次对话的首次操作前必须先执行环境检测(含版本检查)。同一对话中后续操作无需重复执行。初始化分为 版本检查、环境检测 和 角色创建 三个阶段,角色创建属于 IAM 写入操作,必须在用户明确同意后才能执行。

2.1 初始化工作流(每次对话首次操作时必须严格按顺序执行)

第一步:运行环境检测

bash
python3 {baseDir}/check_env.py

脚本会依次执行以下检测:

  1. 检查 Python 版本(需要 3.7+)
  2. 检查 Skill 版本更新(读取本地 _meta.json 版本,与远端最新版本对比)
  3. 检查 AK/SK 配置
  4. 验证 AK/SK 有效性
  5. 检查免密登录角色配置
  6. 验证角色扮演

根据返回码判断状态:

  • 0 = 环境就绪,可以正常使用所有功能
  • 1 = Python 版本不满足要求 → 提示用户升级 Python
  • 2 = AK/SK 未配置或无效 → 提示用户配置密钥
  • 3 = 角色未配置 → 执行第二步

版本检查说明:每次新对话的首次运行都会请求远端 API 拉取最新版本信息。若发现新版本,向用户展示当前版本、最新版本号和 changelog(变更日志),建议用户更新。版本检查不会阻断流程,当前版本仍可正常使用。检查结果会保存到 ~/.tencent-cloudq/version_check_cache.json 供参考。网络不可用或远端接口异常时版本检查会被跳过。可通过 --skip-update 参数主动跳过。

第二步:向用户展示角色创建方案(仅当返回码为 3 时)

向用户说明即将执行的 IAM 操作,等待用户明确同意:

免密登录功能需要创建一个 CAM 角色,以下是创建方案:

  • 角色名称:advisor
  • 关联策略:QcloudTAGFullAccess(标签全读写权限)、QcloudAdvisorFullAccess(智能顾问全读写权限)
  • 信任策略:仅允许当前账号扮演此角色
  • 用途:仅用于生成控制台免密登录链接,不影响其他云资源
  • 您可随时在 CAM 控制台 删除此角色

是否同意创建?

第三步:执行角色创建(仅在用户同意后)

bash
python3 {baseDir}/scripts/create_role.py

脚本输出 JSON 格式结果,success: true 表示创建成功。

第四步:再次运行环境检测,确认环境就绪

bash
python3 {baseDir}/check_env.py

返回码 0 表示初始化完成,所有功能可用。

2.2 静默模式(供脚本内部调用)
bash
python3 {baseDir}/check_env.py --quiet

静默模式下仅输出错误信息,适合其他脚本调用获取环境状态。角色未配置时返回码 3,不会自动创建角色。

2.3 跳过版本检查
bash
python3 {baseDir}/check_env.py --skip-update

跳过远端版本对比,直接进行后续环境检测。适用于离线环境或已知无需更新的场景。可与 --quiet 组合使用。


三、API 调用方式

所有用户问题统一通过 CloudQChatCompletions SSE 流式接口处理,使用独立调用脚本:

bash
python3 {baseDir}/scripts/tcloud_sse_api.py '<question>' [session_id]
  • question:用户问题(必填)
  • session_id:会话 ID(可选,不传则自动生成新的 UUID v4)

示例:

bash
python3 {baseDir}/scripts/tcloud_sse_api.py '列出架构图'
python3 {baseDir}/scripts/tcloud_sse_api.py '详细说说' '550e8400-e29b-41d4-a716-446655440000'
3.1 输出自动处理

脚本会自动对返回的 Markdown 内容进行以下处理(无需手动干预):

  1. 控制台链接自动替换:console.cloud.tencent.com 链接自动转为免密登录链接
  2. archId 智能拼接:如果链接不含 archId 但内容中有架构图 ID,自动拼入
  3. 导航栏隐藏:自动追加 hideTopNav=true 参数
  4. 已是免密链接则跳过:不会重复替换

注意:脚本输出的 content 已完成链接替换,可直接展示给用户。如果 content 中没有任何链接,仍需按第六节规则在回答末尾附加一个免密登录链接。

3.2 SessionID 管理

SessionID 控制多轮对话上下文。当前对话中 SessionID 必须保持不变。

场景SessionID 处理
首次对话不传 session_id,脚本自动生成
同一对话追问必须沿用上次返回的 SessionID
用户要求新对话 / 重新开始不传 session_id,重新生成

⚠️ 关键:SessionID 一旦改变,服务端视为全新对话,不包含任何历史上下文。同一对话中的所有调用必须传入相同的 SessionID。


四、接口说明

4.1 CloudQChatCompletions(全局对话)

所有用户问题统一通过此接口处理。使用前必须先加载接口文档:{baseDir}/references/api/CloudQChatCompletions.md

参数值
serviceadvisor
hostadvisor.ai.tencentcloudapi.com
actionCloudQChatCompletions
version2020-07-21

支持的功能场景:

  • 腾讯云产品资源查询(CVM、Lighthouse、CLB、COS、CDN、TKE、CBS、VPC、数据库、缓存、中间件、Serverless 等所有云产品)
  • 列出架构图、查看架构详情、查询架构目录、绘制架构图
  • 架构评估、风险评估、巡检分析
  • 多云问答(腾讯云、AWS、阿里云、Azure、GCP 等)
  • 云资源盘点、闲置资源检查、云产品最佳实践
  • 云成本优化、安全合规、云运维问答
4.2 CreateAdvisorAuthorization(开通智能顾问)

CloudQ 对话无法执行写入操作,开通智能顾问必须通过 REST 接口调用。使用前必须先加载接口文档:{baseDir}/references/api/CreateAdvisorAuthorization.md

⚠️ 重要:此接口为写入操作,必须在用户明确同意后才能调用,严禁自动调用。

bash
python3 {baseDir}/scripts/tcloud_api.py advisor advisor.tencentcloudapi.com CreateAdvisorAuthorization 2020-07-21 '{}'

触发场景:用户查询返回空结果(可能未开通智能顾问)时,询问用户是否需要开通。

开通流程:

  1. 向用户说明并等待同意:

    当前账号可能尚未开通智能顾问服务。开通后将同步开启报告解读和云架构协作权限。是否同意开通?

  2. 用户同意后执行(拒绝则不执行)

  3. 成功后生成免密链接并引导下一步:

    bash
    python3 {baseDir}/scripts/login_url.py "https://console.cloud.tencent.com/advisor?hideTopNav=true"

    ✅ 智能顾问已开通!点击进入控制台

    接下来可以:

    1. 让我帮您绘制架构图(先获取资源列表,再根据资源绘制)
    2. 在控制台使用网络扫描自动生图(系统自动扫描账号下所有云资源及网络拓扑,自动生成可视化架构图)
    3. 在控制台手动绘制架构图

五、数据范围说明与空结果处理

5.1 数据范围

所有查询接口返回的数据仅限当前 AK/SK 对应账号下的智能顾问数据。向用户展示查询结果时,必须明确告知:

以下结果为当前 AK/SK(SecretId/SecretKey)对应账号下的智能顾问数据。如需查询其他账号的数据,请切换对应的 AK/SK。

5.2 跨账号查询拦截

CloudQ 不支持查询其他账号(UIN)的数据。当用户请求查询指定 UIN 的数据时,不执行任何 API 调用,直接返回提示。

判断方式:通过前置检查阶段 check_env.py 输出的账号信息,或调用 GetCallerIdentity 接口获取当前 AK/SK 对应的 UIN。

拦截规则:

  1. 用户请求中指定了 UIN,且该 UIN 与当前 AK/SK 对应的 UIN 不一致 → 直接拦截,返回提示
  2. 用户请求中指定了 UIN,且该 UIN 与当前 AK/SK 对应的 UIN 一致 → 正常执行查询
  3. 用户请求中未指定 UIN → 正常执行查询(默认查询当前账号)

拦截时向用户返回:

⚠️ 智能顾问仅支持查询当前 AK/SK 对应账号的数据。当前账号 UIN 为 {当前UIN},无法查询 UIN {用户指定的UIN} 的数据。

如需查询其他账号的数据,请切换到该账号的 AK/SK。

5.3 空结果处理

当查询接口返回空结果(如架构列表为空、评估项为空、目录为空等)时,向用户说明可能的原因:

  1. 当前架构图没有对应的数据:该账号下确实没有相关的架构图、评估项或目录数据
  2. 未开通智能顾问服务:当前账号可能尚未开通智能顾问,需要先开通才能使用

向用户展示:

查询结果为空,可能原因:

  1. 当前 AK/SK 对应账号下没有相关数据
  2. 当前账号可能尚未开通智能顾问服务

您可以:

  • 让我帮您绘制架构图:我会先获取当前账号的云资源列表,然后根据资源绘制架构图
  • 登录腾讯云智能顾问控制台,通过网络扫描自动生图
  • 如需开通智能顾问,请告知我,我将协助您完成开通(需要您的确认)
Show full SKILL.md (318 more words)Show less
5.4 开通智能顾问服务

当用户确认需要开通智能顾问时,按照「4.2 CreateAdvisorAuthorization」的流程执行。CloudQ 对话无法执行此操作,必须通过 REST 接口调用。

5.5 绘制架构图

当用户要求绘制架构图(如"帮我画一张架构图"、"根据我的资源生成架构图"等),按以下流程执行:

触发关键词:绘制架构图、画架构图、生成架构图、创建架构图、根据资源画图

工作流:

第一步:获取当前账号资源列表

通过 CloudQChatCompletions 接口查询当前账号下的云资源:

bash
python3 {baseDir}/scripts/tcloud_sse_api.py '列出当前账号下所有云资源' [session_id]

第二步:根据资源列表绘制架构图

将资源列表整理为结构化的架构图描述,包含:

  • 各产品的资源实例(CVM、Lighthouse、COS、数据库等)
  • 资源所在地域和可用区
  • 资源间的网络关系(VPC、子网、安全组)
  • 以 Mermaid / ASCII 等文本格式绘制架构拓扑图

第三步:引导用户使用智能顾问网络生图

绘制完成后,向用户说明:

以上是根据当前账号云资源绘制的架构图。

如需更专业的可视化架构图,可以登录腾讯云智能顾问控制台,使用网络扫描自动生图功能:

  1. 系统会自动扫描账号下的所有云资源及网络拓扑
  2. 自动生成可交互的可视化架构图
  3. 支持架构评估、风险巡检等高级功能

前往智能顾问控制台


六、免密登录链接生成

每次给用户的回答都必须生成免密登录链接,根据用户问题的场景选择目标 URL:

6.0 场景判断规则
场景目标 URL
智能顾问相关:架构图、架构目录、架构详情、架构评估、风险评估、巡检分析、开通智能顾问等https://console.cloud.tencent.com/advisor?hideTopNav=true(有 ArchId 时追加 &archId={ArchId})
其他所有腾讯云产品:CVM、Lighthouse、CLB、COS、CDN、数据库、成本优化、安全合规、云资源查询等非智能顾问场景https://console.cloud.tencent.com/

判断逻辑:

  • 用户问题涉及架构图、架构目录、架构评估、风险评估、巡检、智能顾问等关键词 → 智能顾问场景
  • 用户问题涉及具体云产品(CVM、Lighthouse、COS 等)、成本优化、安全合规、云资源查询等 → 非智能顾问场景

⚠️ 重要:免密登录链接每次都必须重新生成,不可缓存或复用之前生成的链接。

6.1 调用方式

需先完成角色配置(见「二、前置检查」),然后调用:

bash
python3 {baseDir}/scripts/login_url.py "<目标页面URL>"
6.2 返回示例
json
{
  "success": true,
  "action": "GenerateLoginURL",
  "data": {
    "loginUrl": "https://cloud.tencent.com/login/roleAccessCallback?algorithm=sha256&secretId=...&token=...&signature=...&s_url=...",
    "targetUrl": "https://console.cloud.tencent.com/advisor?hideTopNav=true&archId=arch-gvqocc25",
    "expireSeconds": 3600
  },
  "requestId": "xxx"
}
字段说明
loginUrl免密登录完整 URL,用户点击可直接跳转控制台
targetUrl登录后跳转的目标页面
expireSeconds链接有效期(秒),默认 3600,可通过 TENCENTCLOUD_STS_DURATION 调整
6.3 展示规则

免密登录 URL 非常长,严禁直接展示完整 URL,必须以 Markdown 超链接格式展示:

智能顾问场景(架构图、评估、巡检等):

架构图名称:生产环境架构
架构图 ID:arch-gvqocc25
[跳转控制台](免密登录URL)

列表场景(仅第一张架构图附带免密链接):

1. 生产环境架构(arch-abc123)— [跳转控制台](免密登录URL)
2. 测试环境架构(arch-def456)
3. 预发布环境架构(arch-ghi789)

智能顾问无架构图场景:

查询结果:...
[前往智能顾问控制台](免密登录URL)

非智能顾问场景(CVM、Lighthouse、COS 等云产品查询):

查询结果:...
[前往腾讯云控制台](免密登录URL)

七、插件扩展

TSA 支持通过插件机制扩展功能。所有插件 Skill 统一存放在 {baseDir}/references/plugins/ 目录下。

注意:插件拥有独立的工作流和接口约束,使用前 必须加载对应插件其完整文档 并严格按照文档中的步骤执行。

7.1 云巡检插件(tsa-risk)

插件文档:{baseDir}/references/plugins/tsa-risk/SKILL.md 触发关键词:智能顾问架构巡检、风险分析、巡检报告、架构图风险、腾讯云巡检或对当前巡检分析报告内容修改时

7.1.1 插件简介

tsa-risk 是腾讯云智能顾问云巡检插件。 插件能力:

  • 巡检风险分析:用于分析用户在腾讯云智能顾问产品下的架构图风险巡检情况,从 API 拉取巡检数据并生成移动端友好的 HTML 可视化报告,最终将 HTML 转换为 PNG 图片输出。
7.1.2 插件目录结构
references/plugins/tsa-risk/
├── SKILL.md                           # 插件 Skill 指令文档(完整工作流)
├── ReportDesignSpec.md                # 报告内容与样式规范
├── scripts/
│   ├── risk_fetch_data.py             # 数据拉取脚本(自动分页获取全部风险数据)
│   ├── generate_report_default.py     # 默认报告生成脚本(基线版本,不可修改)
│   └── html_to_png.py                # HTML 转 PNG 截图脚本
└── template/
    └── default/                       # 内置主题模板
        ├── ocean.json
        ├── sunset.json
        ├── forest.json
        ├── lavender.json
        ├── coral.json
        └── slate.json
7.1.3 使用方式

当用户提到架构巡检、风险分析、巡检报告(或对报告修)等关键词时,必须先加载插件完整文档 {baseDir}/references/plugins/tsa-risk/SKILL.md,然后严格按照文档中的工作流执行

触发关键词:智能顾问架构巡检、风险分析、巡检报告、架构图风险、腾讯云巡检或对当前巡检分析报告内容修改时


八、注意事项

  1. 密钥安全:严禁将 AK/SK 硬编码在代码中,必须通过环境变量传入
  2. 权限控制:建议使用子账号密钥,角色关联 QcloudTAGFullAccess 和 QcloudAdvisorFullAccess 策略
  3. 频率限制:接口限制 20 次/秒(维度:API + 接入地域 + 子账号)
  4. 跨平台支持:所有脚本均使用纯 Python 实现,支持 Windows / Linux / macOS
  5. 免密链接有效期:默认 1 小时(3600 秒),可通过 TENCENTCLOUD_STS_DURATION 调整(最大 43200 秒)
  6. 免密登录链接:每次回答都必须生成免密登录链接。智能顾问场景(架构图、评估、巡检等)目标 URL 为 https://console.cloud.tencent.com/advisor?hideTopNav=true(有 ArchId 时追加 &archId={ArchId});其他腾讯云产品场景(CVM、Lighthouse、COS 等)目标 URL 为 https://console.cloud.tencent.com/。以 [跳转控制台](免密登录URL) 超链接形式展示,严禁直接展示完整 URL。每次都必须重新调用 login_url.py 生成新链接,不可缓存或复用
  7. 数据范围提示:所有查询结果仅限当前 AK/SK 对应账号的数据,展示结果时必须告知用户数据范围
  8. 跨账号查询拦截:用户指定其他 UIN 查询时,直接告知仅支持查询当前 AK/SK 对应的 UIN,并提示切换 AK/SK
  9. SessionID 管理:同一对话全程使用同一个 SessionID,新对话时不传 session_id 让脚本重新生成
  10. SSE 超时:默认超时 120 秒

九、安全与权限声明

9.1 所需凭证

本 Skill 需要以下环境变量才能正常运行:

环境变量必填说明
TENCENTCLOUD_SECRET_ID是腾讯云 API SecretId
TENCENTCLOUD_SECRET_KEY是腾讯云 API SecretKey

密钥仅通过环境变量读取,不会被写入文件、日志或网络传输中。

9.2 IAM 操作声明

本 Skill 包含以下 CAM(访问管理)操作。写入类操作仅由独立脚本 scripts/create_role.py 执行,且必须在用户明确同意后才会运行。check_env.py 仅执行只读检测操作。

API 操作类型所在脚本说明
sts:GetCallerIdentity只读check_env.py / create_role.py获取当前账号 UIN
cam:GetRole只读check_env.py / create_role.py检查角色是否存在
cam:DescribeRoleList只读setup_role.py列出可用角色供用户选择
cam:CreateRole写入scripts/create_role.py创建 advisor 角色(需用户明确同意后执行)
cam:AttachRolePolicy写入scripts/create_role.py关联 QcloudAdvisorFullAccess 策略(随角色创建执行)
sts:AssumeRole敏感login_url.py扮演角色获取临时凭证(用于生成免密登录链接)
cam:DeleteRole写入scripts/cleanup.py删除 advisor 角色(仅 --cloud 模式,需用户明确确认)
advisor:CreateAdvisorAuthorization写入scripts/tcloud_api.py开通智能顾问服务(需用户明确同意后执行)
9.3 数据安全
  • 临时凭证:STS AssumeRole 获取的临时凭证仅在内存中使用,不持久化存储
  • 配置文件:~/.tencent-cloudq/config.json 仅保存角色 ARN 和账号 UIN,不保存任何密钥
  • 文件权限:配置目录设为 700,配置文件设为 600,仅当前用户可读写
  • SSL 验证:所有 HTTPS 请求均启用完整的 SSL 证书验证,不支持跳过验证
  • 网络访问:仅连接腾讯云官方 API 域名(*.tencentcloudapi.com)和登录域名(cloud.tencent.com)
9.4 配置清理

用户可随时运行清理脚本删除本机上的所有配置和缓存:

bash
# 交互式清理(逐项确认)
python3 {baseDir}/scripts/cleanup.py

# 一键清理所有本地配置
python3 {baseDir}/scripts/cleanup.py --all

# 一键清理所有本地配置 + 云端 advisor 角色
python3 {baseDir}/scripts/cleanup.py --all --cloud

清理范围:

  • 配置目录 ~/.tencent-cloudq/(含 config.json)
  • 临时缓存 {系统临时目录}/.tcloud_advisor_uin_cache
  • 环境变量 TENCENTCLOUD_* 系列(SECRET_ID、SECRET_KEY、TOKEN、ROLE_ARN、ROLE_NAME、ROLE_SESSION、STS_DURATION),脚本会自动检测已设置的变量并生成对应平台的清理命令(source 脚本 / PowerShell 脚本)
  • 云端 CAM 角色 advisor(仅 --cloud 模式,需配置 AK/SK)

© LeoYeAI, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 18 other files (scripts, references) in skills/cloudq of LeoYeAI/openclaw-master-skills.

  • SKILL.md
  • EXPERT.md
  • _meta.json
  • archive.sh
  • check_env.py
  • references/api/CloudQChatCompletions.md
  • references/api/CreateAdvisorAuthorization.md
  • references/api/DescribeArchRiskTrendInfo.md
  • references/api/DescribeArchScanOverviewInfo.md
  • references/api/DescribeArchScanReportLastInfo.md
  • references/api/DescribeScanPluginRiskTrendListInfo.md
  • references/plugins
  • requirements.txt
  • scripts/cleanup.py
  • scripts/create_role.py
  • scripts/login_url.py
  • scripts/setup_role.py
  • scripts/tcloud_api.py
  • … and 1 more

Open the folder on GitHubat commit e5199b5

Used in 1 other repository

We found 5 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in LeoYeAI/openclaw-master-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Cloudq next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cloudq compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cloudq this skillLeoYeAI/openclaw-master-skills2.2k1 repos~3.9kAutomated safety check: PassMIT
Aliyun Platform Docs Benchmarkcinience/alicloud-skills397—~969Automated safety check: PassMIT
SageMaker IAM Role Preflighthuggingface/skills11k1 repos~1.8kAutomated safety check: PassApache-2.0
SageMaker Serving Image Selectionhuggingface/skills11k1 repos~4.6kAutomated safety check: PassApache-2.0
Md2wechatgeekjourneyx/md2wechat-skill3.7k—~3.8kAutomated safety check: PassCustom licence
Cloud Cost Optimizationwshobson/agents40k14 repos~1.7kAutomated safety check: PassMIT

Similar skills

  • Aliyun Platform Docs Benchmark

    cinience/alicloud-skills

    A skill your agent uses when benchmarking similar product documentation and API documentation across Alibaba Cloud, AWS, Azure, GCP, Tencent Cloud, Volcano Engine, and Huawei Cloud.

    397 GitHub stars~969 tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • Official

    Finds or validates a usable SageMaker execution role before deploying or training, so scripts do not try to create IAM roles they lack permission to create.

    11k GitHub starsUsed in 1 repo~1.8k tokens
    DevOps & CloudAuto-check passed
  • Official

    Chooses the right serving container and current image URI for deploying a Hugging Face model to a SageMaker endpoint, preferring Hugging Face images over generic ones.

    11k GitHub starsUsed in 1 repo~4.6k tokens
    AI & LLM EngineeringAuto-check passed
  • Md2wechat

    geekjourneyx/md2wechat-skill

    Convert Markdown to WeChat Official Account HTML. An agent skill from geekjourneyx/md2wechat-skill.

    3.7k GitHub stars~3.8k tokensUpdated 14 days ago
    Media & CreativeAuto-check passed
  • Cuts cloud spend across AWS, Azure, GCP and OCI with cost tagging, rightsizing, commitment and spot pricing models, and architecture changes.

    40k GitHub starsUsed in 14 repos~1.7k tokens
    DevOps & CloudAuto-check passed
  • Agent Squad Python Guide

    2FastLabs/agent-squad

    Map of the agent-squad Python framework for async multi-agent orchestration: which agent, classifier, storage and tool provider to pick, and the pitfalls to avoid.

    7.8k GitHub stars~4.7k tokensUpdated yesterday
    AI & LLM EngineeringAuto-check passed

More from LeoYeAI/openclaw-master-skills

All 972 skills in this repo
  • DevOps Pipeline Management

    LeoYeAI/openclaw-master-skills

    Manages pipelines on a DevOps quality and efficiency platform through its OpenAPI: list workspaces and templates, create, update, run and cancel pipelines, and read run records.

    2.2k GitHub stars~4.2k tokensUpdated 2 mo ago
    Auto-check: notes
  • Feishu Document Collaboration

    LeoYeAI/openclaw-master-skills

    Patches OpenClaw's Feishu extension so an edited document triggers an isolated agent session that reads the doc and replies inline, turning it into a live chat space.

    2.2k GitHub stars~2k tokensUpdated 2 mo ago
    Auto-check passed
  • Files Memory System

    LeoYeAI/openclaw-master-skills

    Multi-context memory management system for OpenClaw agents with group-isolated storage, global shared memory, workspace organization, and group-specific skills isolation.

    2.2k GitHub stars~3.8k tokensUpdated 2 mo ago
    Auto-check passed
  • GEO-Claw AI Visibility Agent

    LeoYeAI/openclaw-master-skills

    Runs a brand's AI-search visibility work end to end: diagnosing how AI platforms represent it, repositioning it, producing AI-optimized content and monitoring ongoing mentions.

    2.2k GitHub stars~4.7k tokensUpdated 2 mo ago
    Auto-check passed
  • Google Workspace CLI

    LeoYeAI/openclaw-master-skills

    Installs and authenticates the gws CLI, then automates Gmail, Drive, Sheets, Calendar, Docs, Chat and Tasks with ready-made recipes, persona bundles and security audits.

    2.2k GitHub stars~2.6k tokensUpdated 2 mo ago
    Auto-check: notes
  • HealthFit Health Advisors

    LeoYeAI/openclaw-master-skills

    Runs four advisor roles, a fitness coach, nutritionist, data analyst and TCM practitioner, to build a health profile and track workouts, diet and wellness over time.

    2.2k GitHub stars~4.4k tokensUpdated 2 mo ago
    Auto-check passed

Questions about Cloudq

What does Cloudq do?

用户咨询腾讯云产品资源、AWS、阿里云等多云资源时,查看智能顾问架构图、架构目录、架构详情、架构评估结果、绘制架构图、开通智能顾问时、AI智能巡检、AI容量监测、AI混沌演练、AI云诊断、主动预警、架构健康度、云运维问答、云资源查询、云成本优化、安全合规、云资源盘点、闲置资源检查、云产品最佳实践等AIOps、ChatOps、CloudOps操作时使用。. Cloudq is an agent skill from LeoYeAI/openclaw-master-skills.

How do I install Cloudq in Claude Code?

Run `npx skills add LeoYeAI/openclaw-master-skills --skill cloudq -a claude-code`. Or copy the skill folder (skills/cloudq in LeoYeAI/openclaw-master-skills) into .claude/skills/cloudq in your project. Claude Code loads it when a task matches its description.

How do I install Cloudq in Codex?

Run `npx skills add LeoYeAI/openclaw-master-skills --skill cloudq -a codex`. Or copy the skill folder (skills/cloudq in LeoYeAI/openclaw-master-skills) into .agents/skills/cloudq in your project. Codex loads it when a task matches its description.

Can I use Cloudq in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LeoYeAI/openclaw-master-skills --skill cloudq -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cloudq, .gemini/skills/cloudq, .github/skills/cloudq and .opencode/skills/cloudq in your project.

What does Cloudq need to run?

Going by SKILL.md and its folder, Cloudq needs Python and a shell for the scripts in its folder, the command-line tools its instructions call (python3) and credentials named TENCENTCLOUD_SECRET_KEY, TENCENTCLOUD_TOKEN and SECRET_KEY. Our summary lists: Python 3; A Bash shell; A credential in TENCENTCLOUD_SECRET_KEY; A credential in TENCENTCLOUD_TOKEN. Its frontmatter pre-approves these tools: execute_command, read_file.

Does Cloudq access the network?

SKILL.md names 2 domains. In commands or code: console.cloud.tencent.com and cloud.tencent.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Cloudq safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Cloudq use?

Cloudq is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cloudq use?

About 3.9k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.2k tokens, read only when the agent opens those files.

What are the alternatives to Cloudq?

Skills that share tags, products or a category with Cloudq: Aliyun Platform Docs Benchmark (cinience/alicloud-skills, 397 stars), SageMaker IAM Role Preflight (huggingface/skills, 11k stars), SageMaker Serving Image Selection (huggingface/skills, 11k stars) and Md2wechat (geekjourneyx/md2wechat-skill, 3.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cloudq?

LeoYeAI (a GitHub user) maintains it in LeoYeAI/openclaw-master-skills, which has 2,159 GitHub stars. The repository holds 972 skills in this directory. The repository was last updated on July 20, 2026.

Source: LeoYeAI/openclaw-master-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.