Taopiaopiao
v0.1.1Provides summaries of movie showtimes, prices, ratings, and basic info from Taopiaopiao's public pages without booking or bulk scraping capabilities.
⭐ 0· 162·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Benign
high confidencePurpose & Capability
Name/description match the SKILL.md: it describes extracting showtimes, prices, ratings and basic info from public movie/venue pages and the skill requests no credentials or unrelated binaries. Requested capabilities are proportional to the stated purpose.
Instruction Scope
SKILL.md is high-level and stays within scope (public page extraction, no booking, no bulk scraping). It recommends opening dynamic pages manually before parsing, which limits automated scraping. However the runtime instructions are vague about the exact scraping mechanism (agent fetch vs. user-provided page), so operational behavior depends on the integrating agent's web-access policies and should be clarified to avoid unintended automated crawling.
Install Mechanism
No install spec and no code files — instruction-only. This minimizes on-disk risk because nothing will be downloaded or executed by the skill itself.
Credentials
No environment variables, credentials, or config paths are requested. Requested access is minimal and appropriate for the stated task.
Persistence & Privilege
always:false (normal). The skill is user-invocable and model invocation is enabled by default (platform default). Autonomous invocation alone is not a security problem, but you should consider whether you want the agent to fetch pages automatically or require user confirmation before each web access.
Assessment
This skill is internally consistent and low-risk because it is instruction-only, asks for no credentials, and explicitly disclaims booking or bulk scraping. Before installing, consider: (1) Source/homepage are not provided — confirm you trust the publisher. (2) Verify compliance with Taopiaopiao's terms of service and robots.txt; do not use it to automate actions the site forbids. (3) Clarify whether the agent will fetch pages autonomously or require the user to open pages first; if you prefer manual control, disable autonomous invocation or require explicit prompts. (4) Enforce rate limits and avoid bulk collection; log accesses and monitor for unexpected behavior. (5) Avoid collecting or storing any personal data found on pages. If you need stronger guarantees, ask the skill author for concrete examples of allowed requests and an explicit statement that no persistent scraping or credential requests will be added in future versions.Like a lobster shell, security has layers — review code before you run it.
latestvk97cx7bznerhcew7nfwvwhtmmx834b0p
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
