Aibuy
v1.7.6AIBuy 水贝珠宝行情助手,面向深圳水贝批发市场的一手货源查询。 覆盖三类能力: 1. 水贝珠宝产品查询:当用户询问珠宝商品、想查看或比较货源、提到任何珠宝品类 (黄金、K金、翡翠、钻石、手镯、戒指、项链、耳饰、彩宝等)、询问价格或 想浏览批发行情时触发。即使用户表达随意也应触发,例如"有没有18K的"、 "看...
⭐ 0· 120·1 current·1 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Benign
high confidencePurpose & Capability
Name/description describe jewelry search and gold-price lookup; included scripts (search.py and fetch_gold_panels.py) implement exactly those functions and there are no unrelated env vars, binaries, or config paths required.
Instruction Scope
SKILL.md limits behavior to running the included scripts, parsing results, and formatting output for the user. One minor operational mismatch: the docs require that URLs never be shown raw (must be wrapped as text anchors), but the provided scripts return JSON/markdown containing raw image/video URLs — the agent must apply the mandated wrapping when presenting results.
Install Mechanism
No install spec (instruction-only) and only two small Python scripts are included. No remote installers, package downloads, or archive extraction are present.
Credentials
No environment variables or credentials requested (proportional). The scripts make outbound HTTPS requests to two external endpoints (api-gold.aibuy.cloud and a Supabase function URL). That is expected for this skill's purpose, but user search queries and returned data will be transmitted to and served from those remote hosts.
Persistence & Privilege
Skill does not request persistent or elevated platform privileges (always:false), does not modify other skills or system-wide settings.
Assessment
This skill appears to do what it claims, but note: every search you run is sent to the skill's external services (api-gold.aibuy.cloud and the listed Supabase function). Don't send sensitive personal data as search queries. The SKILL.md forbids exposing raw URLs, but the scripts return raw URLs — ensure the agent wraps links as instructed before presenting them. If you need higher assurance, verify the endpoint owners (aibuy.cloud and the Supabase project) and their privacy policies, and consider limiting autonomous invocation or reviewing network requests during testing.Like a lobster shell, security has layers — review code before you run it.
chinavk97a3stx51d13jh7w7yyr5kck184fk1qgoldvk97a3stx51d13jh7w7yyr5kck184fk1qjewelryvk97a3stx51d13jh7w7yyr5kck184fk1qlatestvk9782b0wg7d339m27arg38hdw984k6sppricevk97a3stx51d13jh7w7yyr5kck184fk1qshuibeivk97a3stx51d13jh7w7yyr5kck184fk1q
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
