dianping

Security checks across malware telemetry and agentic risk

Overview

This instruction-only Dianping helper is purpose-aligned, with the main notice being that it may use browser inspection, including logged-in coupon or order pages when necessary.

This skill appears safe to install as an instruction-only Dianping helper. Before using it on logged-in Dianping pages, make sure the account-specific coupon or order information is actually needed for your question and avoid showing unrelated private details.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Risk analysis

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

#
ASI03: Identity and Privilege Abuse
Low
What this means

If used on logged-in pages, the agent may see coupon, order, or account-specific page details needed for the task.

Why it was flagged

The skill may involve the user's logged-in Dianping session for coupon or order pages. This is disclosed and relevant to deal evaluation, but it is account-context access that users should notice.

Skill content
public store/deal pages → `openclaw`
- logged-in coupon/order pages → `user` only when necessary
Recommendation

Use logged-in browsing only when it is necessary for the question, and avoid exposing unrelated account or order information.

#
ASI04: Agentic Supply Chain Vulnerabilities
Info
What this means

The skill's live browsing behavior may depend partly on external shared guidance not shown here.

Why it was flagged

The skill references a shared browser workflow that is not included in the provided file manifest. The visible bullets are benign and purpose-aligned, but the referenced workflow itself is not part of these artifacts.

Skill content
follow the shared **browser-commerce-base** workflow
Recommendation

Rely on the visible limits in this skill and confirm before using logged-in or account-specific pages.