Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Cn Ecommerce Search

Search products across 8 Chinese e-commerce platforms: Taobao, Tmall, JD, PDD, 1688, AliExpress, Douyin, XHS. Zero-config — no API keys needed. Powered by Sh...

MIT-0 · Free to use, modify, and redistribute. No attribution required.
5 · 2.1k · 13 current installs · 15 all-time installs
byShopme@shopmeskills
MIT-0
Security Scan
VirusTotalVirusTotal
Suspicious
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
The described capability (searching a unified Shopme product DB across Chinese platforms) is coherent with the skill name and description. However, the SKILL.md requires launching an MCP server with the command 'npx @shopmeagent/cn-ecommerce-search-mcp' even though the skill metadata lists no required binaries. If the agent runtime must run 'npx', that should be declared; otherwise the skill cannot operate as described.
!
Instruction Scope
The SKILL.md tells the agent to run an external MCP server via npx (which will download and execute code from the npm registry) and to call Shopme's API endpoint (default https://api.shopmeagent.com). Aside from an optional SHOPME_API_BASE override, there are no instructions to validate or sandbox that code. There is no indication the MCP package is shipped with the skill; running it gives arbitrary remote code execution scope to the skill at runtime.
!
Install Mechanism
No formal install spec is provided, but the MCP-server setup explicitly uses npx to fetch @shopmeagent/cn-ecommerce-search-mcp. Fetching and executing an npm package at runtime is a moderate-to-high risk operation (network download, code executed locally). The package and its publisher are not linked or documented (no homepage/source), so provenance cannot be verified from the skill metadata.
Credentials
The skill declares no required credentials and only an optional SHOPME_API_BASE env var (to point at a different API). That is proportionate to a search service. However, the SKILL.md omission of 'npx' as a required binary is an inconsistency. The optional SHOPME_API_BASE could be used legitimately for local development but could also be used to redirect traffic to an attacker-controlled API if set improperly.
Persistence & Privilege
The skill does not request always:true, does not declare persistent credentials, and is user-invocable only. There is no declared behavior that modifies other skills or system-wide agent settings. The main privilege concern is runtime execution of the MCP npm package, not elevated platform-level privileges.
What to consider before installing
This skill appears to rely on a remote npm package (@shopmeagent/cn-ecommerce-search-mcp) that will be fetched and executed via 'npx' even though the metadata lists no required binaries. Before installing: (1) verify the npm package and its maintainers (check the package on the npm registry, review source code if available); (2) ensure your agent runtime safely allows 'npx' and you are comfortable with running third‑party code (or run it in a sandbox); (3) be cautious about network access to api.shopmeagent.com and the optional SHOPME_API_BASE — do not set it to an untrusted host; (4) if you cannot verify the MCP package or prefer not to run external code, decline or request a version with embedded, auditable code or an explicit install spec and provenance. The mismatch between the SKILL.md and declared requirements is the main reason for caution.

Like a lobster shell, security has layers — review code before you run it.

Current versionv2.0.0
Download zip
latestvk97exyx7mj0yq63jk2pdw4kdns81gjcw

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

SKILL.md

Chinese E-commerce Product Search

Search and retrieve product information across 8 Chinese e-commerce platforms via the Shopme unified product database.

Zero-config — no API keys required.

When to Use

  • User asks to find a product on any Chinese e-commerce platform
  • User shares a product link and wants details
  • User needs to search Chinese suppliers for a product
  • User asks about prices on Chinese platforms
  • User provides a product URL from Taobao, JD, PDD, 1688, etc.
  • User wants to compare products across platforms

MCP Server Setup

{
  "mcpServers": {
    "cn-ecommerce-search": {
      "command": "npx",
      "args": ["-y", "@shopmeagent/cn-ecommerce-search-mcp"]
    }
  }
}

No environment variables required. Optional:

VariableDefaultDescription
SHOPME_API_BASEhttps://api.shopmeagent.comOverride API endpoint (e.g. http://localhost:8000 for local dev)

Available Tools

search_products

Search products by keyword across platforms.

ParameterTypeRequiredDefaultDescription
keywordstringYesSearch term (Chinese or English)
platformstringNoallFilter by platform (see table below)
sort_bystringNorelevancerelevance, price_asc, price_desc, sales_desc, created_at
pagenumberNo1Page number
limitnumberNo10Items per page (max 50)

get_product_detail

Get detailed info about a specific product by ID or URL.

ParameterTypeRequiredDescription
product_idstringOne of twoProduct ID (recommended, faster)
urlstringOne of twoProduct URL
platformstringNoPlatform hint to speed up lookup

parse_product_link

Parse a product URL to identify the platform and product ID. Runs locally, no API call.

ParameterTypeRequiredDescription
urlstringYesProduct URL or text containing one

Supported Platforms

PlatformCodeStrengthsPrice RangeTypical Buyer
淘宝 TaobaotaobaoLargest selection, consumer goods¥ Low-MidEnd consumers
天猫 TmalltmallBrand flagship stores, higher quality¥ Mid-HighQuality-focused
京东 JDjdFast logistics, electronics, appliances¥ Mid-HighQuality + speed
拼多多 PDDpddGroup-buy deals, lowest prices¥ LowestPrice-sensitive
1688ali1688Wholesale/factory direct, bulk pricing¥ Lowest (bulk)Resellers, businesses
速卖通 AliExpressaliexpressInternational shipping, buyer protection$ MidInternational buyers
抖音 DouyindouyinLive-commerce, trending products¥ Low-MidTrend followers
小红书 XHSxhsCommunity picks, beauty/lifestyle¥ MidYoung women, lifestyle

Supported URL Formats

  • item.taobao.com/item.htm?id=123456
  • detail.tmall.com/item.htm?id=123456
  • detail.1688.com/offer/123456.html
  • item.jd.com/123456.html
  • mobile.yangkeduo.com/goods.html?goods_id=123456
  • aliexpress.com/item/123456.html
  • haohuo.jinritemai.com/...?id=123456
  • mall.xiaohongshu.com/goods-detail/xxx
  • Short links: e.tb.cn/xxx, m.tb.cn/xxx

Price Understanding Guide

  • All platforms except AliExpress return prices in CNY (¥). Rough conversion: 1 USD ≈ 7.2 CNY
  • AliExpress prices in the database are also stored as CNY
  • 1688 prices are factory/wholesale, often 30-70% lower than Taobao for the same product
  • Always consider shipping costs when comparing prices

Search Tips

  1. Chinese keywords get more results on domestic platforms (Taobao, JD, PDD, 1688)
  2. English keywords are auto-expanded with synonyms and word variants
  3. Sort by sales_desc to find popular/trusted products (best on XHS)
  4. Use platform filter to narrow results to a specific platform
  5. Use get_product_detail with a URL directly — no need to parse first

Files

1 total
Select a file
Select a file to preview.

Comments

Loading comments…