Back to skill

Security audit

taobao-listing

Security checks for vulnerabilities and agentic risk

Overview

The skill is internally consistent: it generates Taobao product copy using a local script and guidance files, requests no credentials, and does not perform network or unexpected system access.

This skill appears coherent and self-contained: it runs a local shell script (which embeds Python) to generate Taobao copy and asks for no secrets. Before installing or running it, review the script (scripts/taobao.sh) yourself, ensure you have Python3 installed, and if you’re cautious run it in a sandbox or isolated environment. Because the skill can be invoked by the agent autonomously, consider limiting agent privileges if you do not want it to execute local scripts without prompting. If you need networked features (e.g., real keyword volume data), note this skill does not call external APIs and would need additional trusted integrations to do so.

Static analysis

No suspicious patterns detected.