Back to skill
Skillv1.0.0
ClawScan security
OZON选品货源搜索助手 · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignMar 6, 2026, 8:16 AM
- Verdict
- Benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- This instruction-only skill's requests and instructions are consistent with its stated purpose (OZON product sourcing) and it does not ask for credentials, install code, or perform unexpected actions.
- Guidance
- This skill appears coherent and low-risk: it only provides sourcing advice and static market content and does not request credentials or install code. Before using, remember: 1) verify supplier claims (shipping, certifications, compliance) independently; 2) do not share sensitive account credentials with suppliers; 3) treat pricing and certification guidance as advisory—confirm legal/regulatory requirements for your products and target market; and 4) monitor any automated agent actions (the agent can be invoked by default) if you plan to let it act autonomously on supplier interactions.
Review Dimensions
- Purpose & Capability
- okName/description match the content: SKU/category recommendations, 1688/拼多多 keywords, supplier screening, pricing guidance and market notes—no unrelated credentials, binaries, or capabilities are requested.
- Instruction Scope
- okSKILL.md stays on-topic: it guides conversation flow, recommends categories/keywords, supplier selection criteria and pricing. It does not direct reading of local files, access to environment variables, or transmission to external endpoints.
- Install Mechanism
- okNo install spec and no code files — instruction-only skill with no downloads or executables to run, which minimizes surface area for write/execute behavior.
- Credentials
- okNo environment variables, credentials, or config paths are required. The requested data is purely conversational/market guidance and proportionate to the skill's purpose.
- Persistence & Privilege
- okalways:false and default invocation settings. The skill does not request permanent/system-level privileges or to modify other skills; nothing indicates elevated persistence.
