Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

网约车预订

v1.0.0

企业用车服务助手,支持即时用车、预约用车、接送机、包车等多种用车场景,提供车型选择、费用预估、订单管理等功能。Invoke when user needs to book a car, schedule a ride, airport transfer, or manage car service orders.

0· 77·0 current·0 all-time

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for cs200809/car-hailing-booking.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "网约车预订" (cs200809/car-hailing-booking) from ClawHub.
Skill page: https://clawhub.ai/cs200809/car-hailing-booking
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Required binaries: python3
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install car-hailing-booking

ClawHub CLI

Package manager switcher

npx clawhub@latest install car-hailing-booking
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
!
Purpose & Capability
Name/description (企业用车服务) matches the code's functions (estimate, request, schedule, airport booking, cancel, format). However the SKILL.md explicitly states '必须调用真实用车平台API获取价格和可用车辆' while the bundled Python implementation uses simulated data (random distance, in-code driver DB) and does not call any external ride-platform APIs or request API credentials — this is an incoherence between claimed operation and actual implementation.
Instruction Scope
SKILL.md provides detailed inputs/outputs and UI text and does not instruct the agent to read arbitrary system files or unrelated credentials. However the SKILL.md contains a detected 'unicode-control-chars' injection signal (prompt-injection pattern) and it mandates contacting real platform APIs (contradicted by local simulation). The presence of control characters in the runtime instructions is suspicious and could attempt to manipulate model behavior.
Install Mechanism
No install spec (instruction-only) and required binary is just python3. There are two included .py files but nothing is downloaded from external URLs or installed automatically — low install risk.
!
Credentials
The SKILL.md insists on using '真实用车平台API' which normally requires API keys/credentials, but requires.env is empty and the code doesn't accept or use any external credentials. If the skill were to call real provider APIs, it should declare and request those credentials; absence of any credential handling is an inconsistency.
Persistence & Privilege
Skill is not always-included (always:false) and does not request elevated persistence or modify other skills/config. Default autonomous invocation is allowed (platform default) but is not by itself a new risk here.
Scan Findings in Context
[unicode-control-chars] unexpected: Control-character prompt-injection patterns were detected inside SKILL.md. This is not expected for a straightforward service description and may attempt to influence model evaluation or runtime behavior. The code files themselves appear to be normal local implementations with no external network calls.
What to consider before installing
This skill claims it must call real ride-hailing platform APIs, but the included Python code only simulates behavior (random distances, in-file driver data) and does not accept or request any API keys — that's a mismatch. Additionally, the SKILL.md contains detected unicode control characters which look like a prompt-injection artifact. Before installing or enabling this skill: 1) ask the author whether this is a mock/placeholder or production-ready connector; 2) require the skill to explicitly declare which external APIs it will call and which credentials it needs (and ensure secure secret storage); 3) review any changes that would add network calls (endpoints, URLs) and validate they come from trusted providers; 4) remove or investigate the control characters in SKILL.md and re-run security review; 5) run the skill in a sandboxed environment and test with non-sensitive data first. If you need a production integration, prefer a version that explicitly implements and documents secure API authentication and endpoints.

Like a lobster shell, security has layers — review code before you run it.

Runtime requirements

🚗 Clawdis
Binspython3
latestvk976vz5s0ryc0373ccfztdj38s83zj1f
77downloads
0stars
1versions
Updated 4w ago
v1.0.0
MIT-0

企业用车服务助手 (fb-car-service-skill)

技能描述

企业用车服务助手提供一站式用车解决方案,支持即时用车、预约用车、接送机、包车等多种场景。集成多种车型选择、实时价格预估、智能调度、订单管理等功能,满足企业差旅、商务出行、日常通勤等多样化需求。


⚠️ 【重要约束】

  • 必须调用真实用车平台API获取价格和可用车辆
  • 禁止自行编造价格或车辆信息
  • 预约用车需提前确认司机和车辆
  • 费用预估仅供参考,实际以订单为准
  • 取消订单需遵守平台规则

核心功能

1. 即时用车

  • 实时叫车,快速响应
  • 多种车型选择(经济型、舒适型、商务型、豪华型)
  • 实时位置追踪
  • 预计到达时间
  • 费用预估

2. 预约用车

  • 提前预约,定时出发
  • 重复预约(上下班通勤)
  • 预约提醒
  • 司机信息提前告知

3. 接送机服务

  • 接机:航班动态跟踪,免费等待
  • 送机:准时送达,预留充足时间
  • 车型推荐(根据行李数量)
  • 举牌服务(可选)

4. 包车服务

  • 按天包车
  • 半日包车
  • 长途包车
  • 定制路线

5. 订单管理

  • 订单查询
  • 订单取消
  • 行程分享
  • 电子发票
  • 费用报销

触发场景

  1. 即时叫车

    • "帮我叫辆车去机场"
    • "从公司去上海火车站"
    • "现在需要一辆车"
  2. 预约用车

    • "预约明天早上8点的车去机场"
    • "帮我预约下周三的接送机"
    • "设置每天上下班通勤车"
  3. 接送机

    • "明天下午3点接机,航班CA1234"
    • "预约送机服务,早上6点出发"
    • "需要举牌接机服务"
  4. 包车

    • "包一辆车明天全天商务用车"
    • "需要包车去杭州,当天往返"
    • "包一辆商务车接待客户"
  5. 订单管理

    • "查看我的用车订单"
    • "取消刚才的叫车"
    • "申请发票"

车型说明

车型座位数适用场景价格区间
经济型4座日常通勤、短途出行¥起步价+里程费
舒适型4座商务出行、接待客户经济型×1.3
商务型6-7座多人出行、团队用车经济型×1.8
豪华型4座重要接待、高端出行经济型×2.5

输入参数

即时用车

参数类型必填说明
pickup_locationstring上车地点
dropoff_locationstring下车地点
car_typestring车型:ECONOMY/COMFORT/BUSINESS/LUXURY
ride_typestring用车类型:immediate/scheduled
scheduled_timestring预约时间(预约用车必填)
passenger_countint乘车人数,默认1
luggage_countint行李件数,默认0
remarksstring备注信息

接送机

参数类型必填说明
service_typestringpickup/dropoff
airportstring机场名称
flight_numberstring是(接机)航班号
flight_datestring航班日期
locationstring接送地址
car_typestring车型
passenger_countint人数
luggage_countint行李数

输出格式

叫车结果

{
  "code": 0,
  "msg": "success",
  "data": {
    "order_id": "CAR202403300001",
    "order_status": "pending",
    "ride_type": "immediate",
    "pickup": {
      "location": "北京市朝阳区建国路88号",
      "latitude": 39.9042,
      "longitude": 116.4074
    },
    "dropoff": {
      "location": "北京首都国际机场T3航站楼",
      "latitude": 40.0799,
      "longitude": 116.6031
    },
    "car_type": "COMFORT",
    "car_type_name": "舒适型",
    "estimated_price": {
      "min": 85,
      "max": 110,
      "currency": "CNY"
    },
    "estimated_duration": 45,
    "estimated_distance": 28.5,
    "driver": {
      "driver_id": "DRV001",
      "name": "张师傅",
      "phone": "138****8888",
      "rating": 4.9,
      "vehicle": {
        "plate_number": "京A·12345",
        "brand": "大众",
        "model": "帕萨特",
        "color": "黑色"
      }
    },
    "create_time": "2026-03-30 14:30:00",
    "scheduled_time": null
  }
}

费用预估

{
  "code": 0,
  "msg": "success",
  "data": {
    "pickup": "北京市朝阳区建国路88号",
    "dropoff": "北京首都国际机场T3航站楼",
    "distance": 28.5,
    "duration": 45,
    "price_estimate": {
      "ECONOMY": {
        "min": 65,
        "max": 85,
        "base_fare": 14,
        "mileage_fare": 51,
        "time_fare": 15
      },
      "COMFORT": {
        "min": 85,
        "max": 110,
        "base_fare": 18,
        "mileage_fare": 67,
        "time_fare": 20
      },
      "BUSINESS": {
        "min": 120,
        "max": 150,
        "base_fare": 25,
        "mileage_fare": 95,
        "time_fare": 28
      }
    },
    "surcharges": {
      "night_fee": 0,
      "peak_fee": 0,
      "toll_fee": 15
    }
  }
}

展示格式示例

即时叫车

🚗 即时叫车成功

═══════════════════════════════════════

📍 行程信息
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
🛫 上车地点:北京市朝阳区建国路88号
🛬 下车地点:北京首都国际机场T3航站楼
📏 预估里程:28.5公里
⏱️ 预估时间:45分钟

═══════════════════════════════════════

💰 费用预估
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

车型选择:

🚙 经济型     ¥65-85   | 大众朗逸或同级
🚗 舒适型 ⭐  ¥85-110  | 大众帕萨特或同级
🚐 商务型     ¥120-150 | 别克GL8或同级
🚘 豪华型     ¥180-220 | 奥迪A6L或同级

💡 费用包含起步价、里程费、时长费
💡 高速费、停车费等额外费用需另付

═══════════════════════════════════════

👤 司机信息
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

🚗 车辆信息
   车牌:京A·12345
   车型:大众帕萨特(黑色)

👨‍✈️ 司机信息
   姓名:张师傅
   评分:⭐ 4.9
   电话:138****8888

📍 当前位置:距您2.3公里,约5分钟到达

═══════════════════════════════════════

📋 订单信息
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
订单号:CAR202403300001
状态:🟡 司机接命中
创建时间:2026-03-30 14:30:00

═══════════════════════════════════════

💡 操作提示
• 回复"取消"取消订单
• 回复"分享"分享行程给联系人
• 回复"修改"修改目的地

接送机服务

✈️ 接送机预约成功

═══════════════════════════════════════

📍 服务信息
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
服务类型:接机
机场:北京首都国际机场T3航站楼
航班号:CA1234
航班日期:2026-04-01
预计到达:15:30

🏨 送达地址:北京市朝阳区建国路88号

═══════════════════════════════════════

🚗 车辆信息
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
车型:商务型(别克GL8)
座位数:7座
行李空间:可放4件28寸行李

👨‍✈️ 司机信息
   姓名:李师傅
   电话:139****6666
   评分:⭐ 4.8

═══════════════════════════════════════

💰 费用信息
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
基础费用:¥280
包含:免费等待2小时、高速费
额外费用:超时等待¥50/小时

═══════════════════════════════════════

📋 订单信息
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
订单号:CAR202404010001
状态:🟢 预约成功

💡 温馨提示
• 司机将在航班落地后30分钟内联系您
• 免费等待2小时(从航班实际落地时间计算)
• 请保持手机畅通

═══════════════════════════════════════

💡 回复"查看"查看订单详情
💡 回复"修改"修改预约信息
💡 回复"取消"取消预约

API接口列表

接口名称功能参数
estimate_price费用预估pickup, dropoff, car_type
request_ride即时叫车pickup, dropoff, car_type, passenger_count
schedule_ride预约用车pickup, dropoff, scheduled_time, car_type
book_airport_transfer接送机预订service_type, airport, flight_number, location
book_charter包车预订duration, route, car_type
get_order_detail订单详情order_id
get_order_list订单列表status, start_date, end_date
cancel_order取消订单order_id, reason
share_ride分享行程order_id, contact
request_invoice申请发票order_ids, invoice_type

订单状态说明

状态说明
pending待接单
accepted已接单
arriving司机前往中
arrived司机已到达
in_progress行程进行中
completed已完成
cancelled已取消

费用组成

即时用车费用

费用项说明
起步价包含3公里+10分钟
里程费超出起步里程后按公里计费
时长费低速或等待时按分钟计费
远途费超过15公里后加收
夜间费23:00-05:00加收
动态调价高峰时段可能调价

接送机费用

费用项说明
基础费用一口价,包含机场往返
高速费按实际产生收取
停车费按实际产生收取
等待费免费等待后按小时计费
夜间服务费夜间时段加收

取消规则

取消时间费用
司机接单前免费取消
司机接单后3分钟内免费取消
司机接单后3-5分钟收取¥5取消费
司机已到达收取起步价作为取消费
行程开始后不可取消,按实际费用结算

企业功能

  • 部门用车管理:设置用车权限和额度
  • 费用中心:统一结算、对账
  • 审批流程:超标用车需审批
  • 数据分析:用车报表、费用分析
  • API对接:与企业OA/差旅系统集成

Comments

Loading comments...