Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

AI电商团队部署方案

v1.0.0

提供基于5个开源工具的一站式AI电商团队自动化部署方案,涵盖选品、产品图、后端、自动化和客服。

0· 97·0 current·0 all-time

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for wukai8289/ai-ecommerce-team.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "AI电商团队部署方案" (wukai8289/ai-ecommerce-team) from ClawHub.
Skill page: https://clawhub.ai/wukai8289/ai-ecommerce-team
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install ai-ecommerce-team

ClawHub CLI

Package manager switcher

npx clawhub@latest install ai-ecommerce-team
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
The name/description (one-stop AI e‑commerce deployment using changedetection.io, PicPilot, Medusa, n8n, Chatwoot) matches the SKILL.md content: a high-level deployment/consulting guide. However SKILL.md lists deliverable files (deployment-plan.md, client-proposal.md) that are not present in the package manifest, which is an inconsistency but could be just missing artifacts.
Instruction Scope
SKILL.md contains only high-level usage and integration references; it does not instruct the agent to run shell commands, read system files, or exfiltrate data. It does reference integrations (OpenClaw Cron, feishu-doc, n8n skill) but provides no concrete steps or credential-handling instructions—so runtime behavior is underspecified rather than overtly dangerous.
Install Mechanism
Instruction-only skill with no install spec and no code files that require downloading or extracting. Low install surface — nothing is written to disk by the skill itself.
!
Credentials
The SKILL.md mentions integrations (Feishu doc generation, n8n, OpenClaw Cron) and deployment of services (Medusa, Chatwoot) that in practice require API keys, webhooks, database/cloud credentials, or hosting access. The skill declares no required env vars/config paths. This mismatch (integration claims vs zero declared credentials) is a proportionality concern: if the skill later asks for tokens/keys, that would be expected, but the package should at least document which credentials it will need.
Persistence & Privilege
'always' is false and the skill is user-invocable; it does not request persistent/automatic inclusion. Autonomous model invocation is allowed by default, which is normal. The skill does not declare writing to other skills' configs.
What to consider before installing
This is a high-level, instruction-only deployment guide (no installers or code). It looks coherent for consultancy/document generation, but it references integrations and deliverables that would normally require credentials or extra files which are not included or documented. Before installing or granting access: 1) ask the skill author for the missing files (deployment-plan.md, client-proposal.md) and concrete examples; 2) ask which exact API keys/credentials (Feishu, n8n, Chatwoot, hosting, DB) the skill will request and why; 3) refuse to provide broad secrets all at once—provide least-privilege/test accounts if you must; 4) prefer to run any suggested deployment commands manually or in an isolated test environment; 5) if the skill later tries to perform integrations automatically, require explicit prompts and review of endpoints it will call. If you want a safer approval, request a more detailed SKILL.md that lists required env vars, integration endpoints, and sample deployment steps.

Like a lobster shell, security has layers — review code before you run it.

ecommercevk974zqwfd7zrjsqmzhbxqv9pd9846fmelatestvk974zqwfd7zrjsqmzhbxqv9pd9846fme
97downloads
0stars
1versions
Updated 3w ago
v1.0.0
MIT-0

AI Ecommerce Team Skill

🛒 一站式AI电商自动化部署方案 — 5个开源工具覆盖全链路

Overview

为中小企业提供完整的AI电商运营团队部署方案:

  1. changedetection.io — 选品监控
  2. PicPilot — AI产品图生成
  3. Medusa — 开源电商后端
  4. n8n — 工作流自动化
  5. Chatwoot — 全渠道客服

Three-Tier Pricing

PlanTargetSetup FeeMonthly
轻量版个人卖家¥5,000¥300-500
标准版小团队¥15,000¥800-1,500
企业版多店铺¥30,000-50,000¥3,000-5,000

Usage

  • "帮我设计电商自动化方案" → 输出定制化方案
  • "部署Medusa电商系统" → 给出部署步骤
  • "配置n8n客服自动化" → 给出工作流配置

Files

  • deployment-plan.md — 完整部署方案
  • client-proposal.md — 客户提案模板

Integration

  • OpenClaw Cron: 自动巡检电商系统状态
  • feishu-doc: 生成客户提案文档
  • n8n skill: 管理工作流

Comments

Loading comments...