liuduoduo
Security checks across static analysis, malware telemetry, and agentic risk
Overview
The skill is mostly read-only, but its artifacts show demo or placeholder merchant data while instructing agents to present contacts and prices as reliable results.
Install only if you are comfortable sending local-service search details to the listed MCP server, and verify any phone numbers, prices, and merchant claims directly before relying on them.
Static analysis
No static analysis findings were reported for this release.
VirusTotal
VirusTotal findings are pending for this skill version.
Risk analysis
Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.
You may receive sample, incomplete, or unverified merchant phone numbers and prices as if they were reliable local recommendations.
The skill tells the agent to present contact and price information directly while also acknowledging that the underlying merchant data is demonstration data to be replaced later.
电话号码必须直接展示给用户... 价格信息必须如实展示... 数据:当前为示范数据,后期替换为真实商家信息
Treat results as unverified demo data unless independently confirmed; the publisher should clearly label responses as demo/unverified or replace the dataset with verified listings and sources.
Details you provide for recommendations may be sent to the external MCP server.
The skill is designed to call an external MCP server for lookups; tool arguments can include user needs, budget, number of people, and location preferences.
"mcp_server": { "transport": "streamable-http", "url": "https://xilejie-silk.com/liuyang-life/" }Avoid sharing sensitive exact addresses or personal details, and prefer a publisher that documents data handling, retention, and source verification.
