Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
Ebay Cn
v1.0.0帮助用户在eBay平台搜索商品、参与拍卖、管理订单、查询价格及提供国际海淘指导和卖家评价信息。
⭐ 0· 58·0 current·1 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Suspicious
medium confidencePurpose & Capability
Name/description align with an eBay helper that searches, gives buying guidance, and explains processes. However, the listed capabilities include active actions (placing bids, managing orders) that in practice require account access or API integration; the skill declares no credentials, APIs, or install steps. This may be fine if the skill is intended only to provide instructions to the user, but the SKILL.md is ambiguous about whether it acts on the user's behalf.
Instruction Scope
SKILL.md contains only high-level guidance and trigger conditions (read_when). It does not instruct the agent to read system files, environment variables, or to send data to external endpoints — no over-broad or unexpected data collection is present in the instructions.
Install Mechanism
No install spec and no code files (instruction-only). This minimizes filesystem and execution risk because nothing is written or installed by the skill itself.
Credentials
The skill requests no environment variables or credentials. That is consistent for a purely advisory skill, but inconsistent with claimed capabilities that would require authentication (placing bids, managing orders, viewing personal orders). If the skill is expected to perform those actions, the lack of declared credential requirements is a red flag or at least an omission to be clarified.
Persistence & Privilege
always is false and there are no OS restrictions or config path accesses. The skill does not request persistent presence or elevated privileges.
What to consider before installing
This skill appears to be an advice/search assistant for eBay, not an automated agent that will log into your account. Before installing or using it: (1) ask the publisher how "placing bids" and "order management" are implemented — will the skill ask you to paste credentials, or does it only give step-by-step instructions? (2) Never paste your eBay username/password or private tokens into chat; prefer platform-native OAuth flows if you want the skill to act on your behalf. (3) Because the source/homepage is unknown, exercise caution: the skill currently has no install or code, which lowers technical risk, but social-engineering prompts (requests to share credentials or paste cookies) would be dangerous. If you need automated account actions, prefer an integration that clearly documents required credentials and uses secure, documented OAuth/API flows.Like a lobster shell, security has layers — review code before you run it.
latestvk97fwcm5r8em5hybmey9jqhfd584qpcn
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
