AirShelf Agentic Commerce Platform
v1.3.0Search, compare, and buy products from verified merchants. Returns structured product data with Decision Packs (pros, cons, best_for, allergens, verified pricing) instead of raw web scraping. No CAPTCHAs, no auth required. ~980 products across 10 merchants. Use when user wants to find, compare, or purchase products.
⭐ 4· 1.3k·1 current·3 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Suspicious
medium confidencePurpose & Capability
The name/description claim search, compare, and checkout functionality and the SKILL.md provides concrete curl endpoints that implement those capabilities — this is coherent. However the skill repeatedly claims "verified pricing" and Decision Packs without provenance or merchant-auth evidence; that claim is unexpected for a public, no-auth API and should be treated skeptically.
Instruction Scope
Runtime instructions are narrow and concrete (curl requests to specific endpoints) and do not ask the agent to read local files or system secrets. However the checkout flow and API accept optional fields such as `customer.email` and `agent_id` — these can transmit PII or agent identifiers to an external service. The SKILL.md does not restrict or warn about sending sensitive user data.
Install Mechanism
Instruction-only skill with no install spec or bundled code; the only runtime requirement is curl. This minimizes on-disk risk.
Credentials
The skill declares no required environment variables or credentials (proportional). Still, optional parameters (customer email, agent_id) allow exfiltration of identifying or sensitive data if the agent includes them. Also the skill has no homepage or public source to validate claims, which reduces trust in its data-handling practices.
Persistence & Privilege
always is false and there is no install/persistence behavior described. The skill does not request system-level privileges or modify other skill configs.
What to consider before installing
This skill appears to implement product search/compare/checkout over a public API, but its origin is unknown and it has no homepage or source repo. Before installing: 1) Avoid sending any PII (email, phone, payment info) or your agent's internal identifier in requests — remove or blank `customer.email` and `agent_id`. 2) Test with non-sensitive queries and verify returned merchant/checkout URLs before clicking through. 3) Prefer skills with a documented publisher, homepage, or third-party reviews for commerce/checkout flows. 4) If you must use it for real purchases, confirm merchant links lead to reputable merchant domains and not unexpected redirects. If you cannot confirm provenance, treat it as untrusted and avoid using it for transactions or private customer data.Like a lobster shell, security has layers — review code before you run it.
latestvk97868c7djrsznrfexgp7nsqc180xf4v
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
Runtime requirements
🛒 Clawdis
Binscurl
