Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Benign
high confidencePurpose & Capability
Name/description (BYD parts and accessories) align with the SKILL.md content which describes product search, comparison, and price tracking. There are no unrelated privileges or credentials requested that would be inconsistent with a shopping helper.
Instruction Scope
The SKILL.md contains only high-level guidance for product search and recommendations. It does not instruct the agent to read local files, access unrelated environment variables, or transmit arbitrary system data. It does include a generic note to 'Set up API credentials in environment variables as needed' but does not request or reference specific secrets.
Install Mechanism
No install spec and no code files are present — nothing will be written to disk or automatically installed by this skill.
Credentials
The skill declares no required environment variables or credentials. The only mention of credentials is a generic instruction to configure platform-specific API keys as needed in future integrations; that is proportional to a shopping integration but is not currently present.
Persistence & Privilege
The skill is not always-enabled and uses normal autonomous-invocation defaults. It does not request persistent system-level privileges or attempt to modify other skills or agent-wide settings.
Assessment
This skill is instruction-only and currently asks for no credentials or installs, which is coherent for a shopping helper. Before installing or using it in production, consider: (1) the author and source are unknown and there is no homepage—ask for provenance if that matters to you; (2) future versions mention platform API integration and 'full autonomous purchasing' — if/when that appears, review exactly which API keys or payment capabilities the skill requires and whether you want the agent to be able to complete purchases autonomously; (3) only provide platform-specific API keys (e.g., a store API key) when you understand their scope and rotate/revoke them if needed. If you need stronger guarantees, request a version that lists exact APIs/endpoints it will call and explicit env var names before granting credentials or enabling autonomous actions.Like a lobster shell, security has layers — review code before you run it.
latestvk97ajmj2xd8pwmwe5zksf435md84119d
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
Runtime requirements
🛒 Clawdis
