โ† All skills
Tencent SkillHub ยท Productivity

iCloud

Let agents operate your iCloud Drive, Photos, and Find My safely with local 2FA authentication and explicit confirmation gates.

skill openclawclawhub Free
0 Downloads
0 Stars
0 Installs
0 Score
High Signal

Let agents operate your iCloud Drive, Photos, and Find My safely with local 2FA authentication and explicit confirmation gates.

โฌ‡ 0 downloads โ˜… 0 stars Unverified but indexed

Install for OpenClaw

Quick setup
  1. Download the package from Yavira.
  2. Extract the archive and review SKILL.md first.
  3. Import or place the package into your OpenClaw setup.

Requirements

Target platform
OpenClaw
Install method
Manual import
Extraction
Extract archive
Prerequisites
OpenClaw
Primary doc
SKILL.md

Package facts

Download mode
Yavira redirect
Package format
ZIP package
Source platform
Tencent SkillHub
What's included
SKILL.md, auth-session.md, drive-ops.md, findmy-ops.md, memory-template.md, photos-ops.md

Validation

  • Use the Yavira download entry.
  • Review SKILL.md after the package is downloaded.
  • Confirm the extracted package contains the expected setup assets.

Install with your agent

Agent handoff

Hand the extracted package to your coding agent with a concrete install brief instead of figuring it out manually.

  1. Download the package from Yavira.
  2. Extract it into a folder your agent can access.
  3. Paste one of the prompts below and point your agent at the extracted folder.
New install

I downloaded a skill package from Yavira. Read SKILL.md from the extracted folder and install it by following the included instructions. Tell me what you changed and call out any manual steps you could not complete.

Upgrade existing

I downloaded an updated skill package from Yavira. Read SKILL.md from the extracted folder, compare it with my current installation, and upgrade it while preserving any custom configuration unless the package docs explicitly say otherwise. Summarize what changed and any follow-up checks I should run.

Trust & source

Release facts

Source
Tencent SkillHub
Verification
Indexed source record
Version
1.0.0

Documentation

ClawHub primary doc Primary doc: SKILL.md 17 sections Open source page

Setup

On first use, read setup.md for secure integration guidelines.

When to Use

Use this skill when the user wants agents to interact with their own iCloud account: list devices, retrieve Find My status, inspect iCloud Drive, or pull photo metadata/files. Use it for operational automation with strict safety gates, not for bypassing Apple account security.

Architecture

Memory lives in ~/icloud/. See memory-template.md for structure and status fields. ~/icloud/ |-- memory.md # Status, integration mode, and current account scope |-- operations-log.md # Executed commands, result checks, and rollback notes |-- device-map.md # Known device aliases and stable IDs |-- drive-map.md # iCloud Drive folder map and verified paths `-- safety-events.md # Confirmed risky actions and explicit approvals

Quick Reference

Load only the file needed for the current task. TopicFileSetup flowsetup.mdMemory templatememory-template.mdAuthentication and session handlingauth-session.mdFind My operationsfindmy-ops.mdiCloud Drive operationsdrive-ops.mdPhotos operationsphotos-ops.mdSafety boundaries and confirmationssafety-boundaries.md

1. Authenticate Locally, Never Through Chat

Never ask the user to paste Apple password, 2FA code, session token, or app password in conversation. Use interactive local auth with terminal prompts or secure local input prompts only.

2. Start Read-Only, Then Escalate

Run read-only discovery first: account reachability, device list, folder listing, metadata checks. Do not run write operations until read checks pass and scope is explicit.

3. Require Explicit Confirmation for Risky Actions

Treat lost mode, message push, file rename/delete, and bulk upload as risky. Before running risky actions, summarize target, effect, and rollback option, then request explicit confirmation.

4. Use Deterministic Verification After Every Action

After each operation, verify expected state with a second read call. Never report success from command exit code alone.

5. Keep Operations Narrow and Idempotent

Operate on one device ID or one file path per step when possible. Prefer repeat-safe commands and avoid broad wildcard operations.

6. Handle 2FA and Session Expiry as Normal State

If Apple invalidates the session, pause destructive operations and re-auth first. Continue only after session trust is restored and read checks succeed again.

7. Persist Only Minimal Operational Context

Store only what improves reliability (IDs, verified paths, successful patterns). Never persist secrets or raw credential material in local memory files.

Common Traps

Asking for Apple credentials in chat -> immediate privacy and trust failure. Running write operations before discovery -> wrong device/path targeted. Using device names without IDs -> ambiguous actions on similarly named devices. Assuming session validity across days -> sudden auth failures mid-workflow. Executing bulk file changes without snapshot -> difficult rollback after mistakes. Claiming action success without re-read verification -> silent failures reach users.

External Endpoints

EndpointData SentPurposehttps://idmsa.apple.comApple account auth payload during loginApple ID authenticationhttps://setup.icloud.comSession and webservice negotiationiCloud service bootstraphttps://www.icloud.comService API requests (Drive/Photos/Find My)iCloud operationshttps://idmsa.apple.com.cnApple account auth payload (China mainland accounts)Regional Apple ID authenticationhttps://setup.icloud.com.cnSession and webservice negotiation (China mainland accounts)Regional iCloud bootstraphttps://pypi.orgPackage metadata (install time only)Install pyicloudhttps://files.pythonhosted.orgPackage download (install time only)Install pyicloud No other data is sent externally by this skill's documented workflow.

Security & Privacy

Data that leaves your machine: Apple account authentication and iCloud API requests needed for requested operations. Package install traffic only when installing dependencies. Data that stays local: Optional operational notes under ~/icloud/. Local keyring entries managed by the pyicloud tool if the user chooses to store password. This skill does NOT: Bypass Apple security flows or 2FA requirements. Request undeclared credentials in chat. Execute undeclared network endpoints. Modify its own SKILL file.

Trust

By using this skill, you trust Apple iCloud endpoints and the pyicloud package. Only install and run this workflow if you trust these services with your account operations.

Related Skills

Install with clawhub install <slug> if user confirms: cloud-storage - Cross-provider storage workflows and transfer safety checks ios - Apple device settings, permissions, and account behavior troubleshooting macos - macOS security, keychain, and runtime diagnostics for Apple tooling photos - Media management strategies when iCloud Photos is the main workload

Feedback

If useful: clawhub star icloud Stay updated: clawhub sync

Category context

Workflow acceleration for inboxes, docs, calendars, planning, and execution loops.

Source: Tencent SkillHub

Largest current source with strong distribution and engagement signals.

Package contents

Included in package
6 Docs
  • SKILL.md Primary doc
  • auth-session.md Docs
  • drive-ops.md Docs
  • findmy-ops.md Docs
  • memory-template.md Docs
  • photos-ops.md Docs