جاك العلم

v2.0.3

Personal Shopper — multi-agent product/service research and recommendation for Saudi Arabia. USE WHEN: - User asks to find, compare, recommend, or buy a prod...

0· 659·2 current·2 all-time
byAbdullah AlRashoudi@abdullah4ai
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Benign
high confidence
Purpose & Capability
Name/description (Personal Shopper for Saudi Arabia) align with the declared behavior: multi-agent web research, price checks, coupons, and an HTML report. Tools referenced (web_search, web_fetch, camofox, sessions_spawn) are expected for scraping JS-heavy retailer pages and producing a report. No unrelated credentials, binaries, or config paths are requested.
Instruction Scope
SKILL.md confines actions to web searches/fetches, spawning sub-agents for structured research, and writing HTML to shopping-reports/. It explicitly limits file reads to references/ and shopping-reports/screenshots/. Minor note: the HTML template includes external Google Fonts and may reference retailer-hosted product images (causing external requests when the report is opened); this is expected for a report but is an external-network behavior to be aware of.
Install Mechanism
Instruction-only skill with no install spec and no code files — lowest install risk. Nothing will be downloaded or written beyond the generated reports (shopping-reports/).
Credentials
The skill requests no environment variables or credentials and only reads its own reference files. Required access (web fetches, occasional headless snapshots via camofox) is proportionate to its stated task of live retail research.
Persistence & Privilege
always:false (not force-included). disable-model-invocation:false is the platform default; the skill will be invocable and may spawn sub-agents during runs, which is coherent with its orchestration role. It only writes reports to shopping-reports/ and does not request system-wide changes.
Assessment
This skill appears internally consistent and lightweight: it does live web searches (including headless snapshots for JS-heavy pages) and writes an Arabic RTL HTML report to shopping-reports/. It asks for no credentials and has no installer. Things to consider before installing: 1) Reports embed external fonts and may link to retailer images and product pages — when you open a generated report your browser may make external requests. 2) The skill will follow links to third-party sellers; always verify seller reputation and URLs before clicking 'اشتري الآن' links. 3) The skill uses a headless/browser-fallback tool (camofox) for some pages — this is expected but means web content will be rendered/extracted; review network allowlist settings if you want to restrict which domains the skill may contact. 4) Autonomous invocation is allowed by default on the platform (not set to always:true here); if you want manual control, keep it user-invocable only. Overall: coherent for its purpose, but treat generated links and external resources with normal caution.

Like a lobster shell, security has layers — review code before you run it.

latestvk978s64qk0kfsh3tq0p1n359nh81frex

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Comments