Back to skill
Skillv2.0.2
ClawScan security
Taobao Shopping · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignMar 31, 2026, 10:00 AM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- The skill's requirements and runtime instructions match its stated purpose (Taobao listing evaluation) and it does not request unrelated credentials, installs, or elevated persistence.
- Guidance
- This skill is coherent with its stated purpose and does not request credentials or installs. Before enabling it, confirm the agent/tool you use provides safe browser access (so the skill can inspect Taobao pages) and avoid pasting any account credentials or payment details into prompts. If you need cross-platform price comparisons or seller authenticity checks involving official store verification, use the skills listed in the documentation (e.g., taobao-competitor-analyzer, tianmao) instead.
Review Dimensions
- Purpose & Capability
- okName, description, and SKILL.md all describe Taobao listing and seller evaluation. No unexpected env vars, binaries, or external services are requested.
- Instruction Scope
- okInstructions are limited to collecting browser-visible information from Taobao pages (title, price, store badges, URLs, etc.) and producing a compact recommendation; they explicitly forbid hidden APIs, scrapers, or payment automation.
- Install Mechanism
- okInstruction-only skill with no install spec and no code files — nothing will be written to disk or downloaded by the skill itself.
- Credentials
- okNo required environment variables, credentials, or config paths are declared or referenced; requested data fields are limited to page-visible shopping signals.
- Persistence & Privilege
- okalways is false and autonomous invocation is platform-default; the skill does not request permanent/system-wide privileges or to modify other skills.
