Extrabux返利助手

v0.1.0

Extrabux海淘返利平台工具,中英双语界面,覆盖10000+海外商家,为全球华人提供购物现金返利服务。

0· 42·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Pending
View report →
OpenClawOpenClaw
Benign
high confidence
Purpose & Capability
The name/description (Extrabux cashback assistant) matches the content of SKILL.md: trigger phrases, claimed capabilities, and an output template. The skill does not request unrelated resources or credentials. Note: the SKILL.md is a high-level template and does not include integration details or a data source, which reduces verifiability but does not create an incoherence.
Instruction Scope
The runtime instructions are limited to metadata, claimed features, trigger phrases, and an output format. They do not instruct reading files, accessing environment variables, or sending data to external endpoints. However, the instructions are vague about how merchant data, cashback rates, or links are obtained (no API, scraping, or data source specified). This is functional vagueness rather than a security mismatch.
Install Mechanism
No install specification or code files are provided (instruction-only). This minimizes risk from downloads or on-disk code execution.
Credentials
The skill declares no required environment variables, credentials, or config paths. There is no disproportionate request for sensitive secrets.
Persistence & Privilege
The skill does not request persistent/always-on presence (always: false) and does not modify system or other skills' configurations. Model invocation is allowed (default), which is normal; this combined with no requested credentials presents no additional concern.
Scan Findings in Context
[NO_SCAN_TARGETS] expected: This is an instruction-only skill with no code files; the regex/static scanner had nothing to analyze. That is expected for a prompt/template-style skill.
Assessment
This skill appears internally consistent and low-risk because it’s just an instruction/template and requests no credentials or installs. However, it is vague about how it gets real cashback data or links — there's no homepage, source, or API specified. Before using or trusting results: prefer a skill with a clear source or official integration, avoid entering any personal credentials into chat responses, and verify any cashback links or payment instructions independently (e.g., on the official Extrabux site). If you need stronger assurance, ask the publisher for integration details or test the skill in a restricted environment first.

Like a lobster shell, security has layers — review code before you run it.

latestvk97fy2rafdvhds1czkjb61abgs83r2ax

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Comments