Ruofan Bargain Arena

v2.1.0

若饭砍价擂台 — 和若小饭讨价还价,赢取专属优惠码

0· 115·0 current·0 all-time
by若饭实验室@ruffood·duplicate of @ruffood/bargins
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Benign
high confidence
Purpose & Capability
The name/description match the runtime instructions: the skill guides the agent to join and converse with Ruofan's bargain API endpoints. It requires only outbound network access which is appropriate for calling https://www.ruffood.com APIs. Minor provenance note: the skill has no homepage and the source/owner in the registry is not human-readable, so you don't have an external reference for the publisher, but this does not make the requested capabilities disproportionate.
Instruction Scope
SKILL.md only instructs API calls to the documented ruffood.com endpoints, to save and reuse a session_token, to relay AI replies and offer amounts, and to stop after deal/no_deal. It does not instruct reading local files or unrelated environment variables. However, it expects the agent to persist the session_token (no secure-storage guidance is provided) and to forward user-provided messages verbatim, which has privacy implications—especially since the activity may be publicly displayed on the vendor site.
Install Mechanism
Instruction-only skill with no install spec and no bundled code — lowest install risk. No downloads, packages, or binaries are required.
Credentials
The skill does not request environment variables, credentials, or config paths. Network outbound permission is proportionate for calling the external bargain API. There are no unrelated secrets requested.
Persistence & Privilege
The skill is not always-included and does not request elevated platform privileges. It does rely on storing a session_token across calls; the SKILL.md does not specify where/how to store it or retention policy. Also note the agent may invoke the skill autonomously (platform default); if you want to avoid automated interactions, you should restrict invocation to manual/user triggers.
Assessment
This skill appears to do what it says: it will call Ruofan's bargain API to join a session, exchange messages, and report coupon codes. Before installing, consider: (1) provenance — the skill has no homepage and the publisher identity is minimal, so only install if you trust the registry owner; (2) privacy — the activity is publicly displayed on the vendor site and the skill stores a session_token (avoid sending sensitive personal data in messages); (3) network calls — it will contact https://www.ruffood.com, so verify that domain if you have concerns; (4) invocation behavior — the skill can be invoked autonomously by the agent by default, so if you want manual control, restrict usage to explicit commands. If any of these are unacceptable, do not enable the skill or request a version with clearer provenance and explicit token-storage guidance.

Like a lobster shell, security has layers — review code before you run it.

latestvk9710k0g5mewqmfwpn5aq5cwhn83481w

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Comments