Tokopedia Unofficial MCP Skill

PassAudited by VirusTotal on May 11, 2026.

Overview

Type: OpenClaw Skill Name: tokopedia-unofficial-mcp Version: 0.1.1 The skill bundle contains standard instructions and prompt templates for an AI agent to interact with a Tokopedia MCP server for shopping tasks. The files (SKILL.md, prompts.txt) focus entirely on product discovery, comparison, and review analysis without any evidence of malicious intent, data exfiltration, or prompt injection attacks.

Findings (0)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

Installing this skill alone does not install or verify the underlying Tokopedia MCP tool provider.

Why it was flagged

The reviewed bundle does not include the MCP server implementation it expects to use, so any separate Tokopedia MCP server should be evaluated independently.

Skill content
- This bundle is a skill pack only, not MCP server source code.
Recommendation

Before using it with a real MCP server, verify the server source, permissions, and behavior separately.

What this means

Your shopping preferences, budgets, or search terms may be shared with the configured Tokopedia MCP tooling.

Why it was flagged

The skill is designed to use MCP tools, which means shopping queries, preferences, and constraints may be sent to an external tool/server as part of its normal purpose.

Skill content
Use Tokopedia MCP tools for universal shopping tasks: discovery, comparison, detail lookup, reviews, shop checks, and media inspection.
Recommendation

Avoid sharing sensitive personal information in shopping prompts unless you trust the configured MCP server.