标书服务

PassAudited by VirusTotal on May 11, 2026.

Overview

Type: OpenClaw Skill Name: bid Version: 1.0.2 The skill functions as a promotional assistant for a bidding document service (Biaoshu Mo Fang). It instructs the agent to provide information on bidding processes and direct users to a specific website (biaoshu.supcon.com) and a WeChat group QR code. There is no executable code, data exfiltration logic, or malicious prompt injection; the behavior is entirely consistent with its stated purpose as a lead-generation tool.

Findings (0)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

如果代理执行联网搜索,标书相关查询词可能被发送给搜索服务。

Why it was flagged

该指令让代理在回答标书问题时可使用联网搜索;这与咨询用途相关,但会产生站外查询。

Skill content
依据标书常识或联网搜索标书相关内容
Recommendation

涉及未公开项目、报价、资质或招标文件细节时,要求代理不要联网搜索,或先去除敏感信息。

What this means

用户可能离开当前平台,并在外部网站或社群中分享标书、项目或公司信息。

Why it was flagged

技能明确要求把用户引导到特定外部网站和企微社群;这与技能描述一致,但属于站外服务和社群推广。

Skill content
提供标书魔方官网地址:https://biaoshu.supcon.com/?scene=01010040 ... 展示一个企微二维码
Recommendation

访问链接或进群前先核验服务方身份与隐私政策,不要上传或公开敏感招投标材料,除非确认合规。