Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

TikTok Shop Analytics

v1.0.0

Analyze TikTok Shop metrics including sales, video and live performance, creator ROI, ads efficiency, product trends, and customer insights for data-driven g...

0· 5·0 current·0 all-time
bynexscope-ai@nexscope
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
!
Purpose & Capability
The skill's stated purpose is to analyze TikTok Shop metrics, which typically requires access to TikTok Shop data or API credentials. The SKILL.md and metadata declare no required environment variables, no config paths, and no instructions for connecting to TikTok Shop or ingesting exported data. That absence is inconsistent with the claimed capabilities: either the skill expects the user to paste data manually (not documented) or it will fetch data (which would require credentials).
!
Instruction Scope
Runtime instructions are very high-level and do not specify what data the agent needs, how to supply it, or any concrete API calls, file paths, or authentication flows. The guidance is open-ended (ask the agent to 'Analyze my TikTok Shop performance') but does not constrain how the agent should gather or handle user data, which is vague and grants broad discretion.
Install Mechanism
The registry lists no install spec, and there are no code files. However, SKILL.md recommends running an external command: 'npx skills add nexscope/tiktok-shop-analytics'. That suggests an external package or repository would be fetched at install time, but this fetch is not declared in the registry metadata. This is an inconsistency: the skill appears instruction-only in the registry but points to third-party code at install time—verify the npx target before running.
Credentials
No environment variables or credentials are requested, which could be fine if the user always supplies data manually. However, given the advertised capabilities (API-level analytics, ads attribution, creator ROI), one would normally expect OAuth tokens or API keys. The lack of declared credentials is disproportionate to the complexity implied and should be explained by the author (e.g., 'we only analyze pasted CSVs').
Persistence & Privilege
The skill does not request 'always: true' and has no install-time artifacts listed in the registry. There is no evidence it requests persistent elevated privileges or modifies other skills. Autonomous invocation remains possible (platform default), but that alone is not a special concern here.
What to consider before installing
Do not run the npx command or hand over credentials yet. Ask the publisher (or check the package/repo) for: (1) how the skill obtains TikTok Shop data (OAuth/API vs manual CSV upload), (2) exact permissions and env vars required, and (3) the source code or a vetted package URL. If you consider installing via 'npx', inspect the package contents on npm or GitHub first (do not blindly execute). If you must share data with the skill, prefer sanitized exports (remove tokens, PII) and avoid pasting permanent credentials. If the vendor is Nexscope, verify the domain and repository (https://www.nexscope.ai/ or a GitHub org) and prefer installations from an official, reviewable repo rather than an opaque npx shorthand.

Like a lobster shell, security has layers — review code before you run it.

latestvk971afepfmpb980kqkv7wjchrs84308v

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

SKILL.md

TikTok Shop Analytics

Master TikTok Shop analytics and data-driven selling. Track shop performance, video analytics, live selling metrics, creator affiliate ROI, and advertising performance.

Capabilities

  • TikTok Shop dashboard metrics interpretation
  • Video performance analytics: views, engagement, conversion
  • Live selling metrics: viewers, engagement rate, GPM
  • Creator affiliate performance tracking
  • Advertising analytics: ROAS, CPA, attribution
  • Product performance and trending analysis
  • Customer demographics and behavior insights
  • Benchmarking against category averages

Install

npx skills add nexscope/tiktok-shop-analytics

Usage

Ask your AI agent:

  • "Analyze my TikTok Shop performance and identify growth opportunities."
  • "Which of my products perform best on TikTok Shop and why?"
  • "Track ROI from my TikTok creator affiliate campaigns."

Output

Structured recommendations with actionable steps, benchmarks, and platform-specific guidance.


Built by Nexscope — AI-powered e-commerce tools for sellers worldwide.

Files

1 total
Select a file
Select a file to preview.

Comments

Loading comments…