Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
国顺工程智能套件
v1.0.0国顺工程智能套件 - 整合招标文件分析、投标助手、合同风险审核三大核心功能。支持工程企业从招标获取、技术方案生成到合同风险管控的全流程AI辅助。由江苏国顺智能科技有限公司出品。
⭐ 0· 49·0 current·0 all-time
by@jimmygx
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Suspicious
high confidencePurpose & Capability
技能名称、描述和提供的脚本/SKILL.md 在功能上相互一致:招标解析、投标方案生成、合同审核三大模块都有配套模板和脚本。没有不相称的外部凭据、二进制依赖或与目的无关的安装要求。唯一需要注意的地方是多个参考模板中包含关于“补充/虚构业绩”的示例文本,这与公开宣称的“辅助合规投标/合同审核”目的不一致。
Instruction Scope
SKILL.md 明确要求用户上传 PDF/DOCX 或粘贴合同/招标文本,脚本也只处理本地文本输入;没有指示读取系统级配置或额外环境变量。但文档与模板中多处出现鼓励或示例性的文字,建议在资质自检/业绩不足时“补充1个虚构案例(需说明)”或“业绩不足需补充近3年合同或虚构”。这实际上指示代理生成或接受伪造业绩信息——超出正常自动化辅助的合理范围并具有法律与合规风险。
Install Mechanism
无安装规范(instruction-only 加上一些本地脚本),未下载外部二进制或从不明 URL 拉取代码。脚本是离线 Python 占位实现,没有自动网络调用或安装步骤声明,风险较低。
Credentials
声明不要求任何环境变量、凭据或配置路径,脚本代码也未读取环境凭证或敏感系统路径。所需权限与技能功能相称。
Persistence & Privilege
flags 显示 always:false,且默认允许模型调用(正常)。技能没有声明修改其他技能或系统级配置,也不请求常驻权限。
What to consider before installing
This skill appears to implement the advertised bidding/contract workflows and contains useful templates and simple local scripts. However, multiple templates and guidance lines explicitly suggest fabricating or supplementing "虚构"(虚构业绩、补充虚构合同等),which poses legal, regulatory and reputational risk if followed. Before installing or using:
- Do NOT follow or enable any advice that encourages fabricating performance records, fake contracts, or unverifiable contact details — this can be illegal and expose your company to sanctions and contract disputes.
- Require human review: enforce that all AI-generated proposals, qualification checks, and contract redlines are reviewed and approved by qualified staff (legal, compliance, project managers) before any submission.
- Remove/modify templates: ask the skill author to remove any examples that suggest falsification and replace them with guidance on legitimate remedial actions (e.g., joint ventures, subcontracting, lawful evidence collection).
- Sensitive data: avoid uploading unredacted sensitive contracts or PII unless you trust the runtime environment and have a retention/privacy policy; the skill does not declare how uploaded data is stored/handled.
- Autonomous use: although always:false, if you allow autonomous invocation, ensure the agent is blocked from taking external actions (submitting bids, sending emails) without explicit human confirmation.
If the developer removes/rewrites the parts that encourage falsification and documents how uploaded files are handled, this assessment could shift to benign.Like a lobster shell, security has layers — review code before you run it.
latestvk970ja7s60tw5z01ph60abp925847nmx
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
