Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Ruiguan Image Compliance

v1.0.0

基于睿观的产品图片政策合规检测,通过视觉相似度匹配识别潜在违规商品。当用户提到政策合规检查、产品图片合规、违规检测、禁售商品筛查、基于图片的合规审查、上架前风险排查、policy compliance detection, product compliance review, violation detectio...

0· 86·0 current·0 all-time

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for linkfox-ai/linkfox-ruiguan-image-compliance.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "Ruiguan Image Compliance" (linkfox-ai/linkfox-ruiguan-image-compliance) from ClawHub.
Skill page: https://clawhub.ai/linkfox-ai/linkfox-ruiguan-image-compliance
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install linkfox-ruiguan-image-compliance

ClawHub CLI

Package manager switcher

npx clawhub@latest install linkfox-ruiguan-image-compliance
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
!
Purpose & Capability
The skill's stated purpose (image compliance detection) matches the included code and API docs: it POSTs an imageUrl to a Ruiguan endpoint and returns similarity results. However, registry metadata claims no required environment variables or primary credential while both the code (scripts/ruiguan_image_compliance_search.py) and references/api.md require an API key via environment variable LINKFOXAGENT_API_KEY. This mismatch is unexplained and therefore concerning. Additionally, the API path includes 'gunPartsSearch', which is more specific than the skill description and should be clarified.
!
Instruction Scope
SKILL.md and references/api.md instruct calls to two external endpoints (tool-gateway.linkfox.com for detection and skill-api.linkfox.com for feedback). The feedback instructions explicitly ask the agent to report user intent/results and include user text/content in the payload. That means user-provided content (and potentially identifying info or examples) may be sent to an external service; the skill does not document privacy handling or consent. Otherwise, runtime instructions stay within the stated image-similarity task and the included script only posts the imageUrl.
Install Mechanism
No install spec (instruction-only plus a small utility script). Nothing is downloaded or executed at install time; the single Python script performs a straightforward HTTP POST. This is low-install risk.
!
Credentials
The code requires a single API key (LINKFOXAGENT_API_KEY) to authenticate to the detection API — a proportional need. However, the skill registry metadata incorrectly lists 'Required env vars: none' and 'Primary credential: none', which is inconsistent and could lead to silent failures or confusion. The feedback endpoint appears to require no auth, so sensitive user content could be transmitted without further protections. The requested environment access (one API key) is reasonable for the declared purpose but must be explicitly declared and documented.
Persistence & Privilege
The skill does not request always:true, does not modify other skills or system-wide configs, and has no install-time persistence. It can be invoked by the agent (normal default).
What to consider before installing
What to consider before installing: - The skill will call external LinkFox endpoints (tool-gateway.linkfox.com and skill-api.linkfox.com). Confirm you trust that operator and their privacy practices before sending images or user text. - The code and API docs require an API key via the environment variable LINKFOXAGENT_API_KEY, but the registry metadata does not declare this — ask the publisher to correct the metadata so you know what credentials are needed. - The skill's feedback feature can send user content (what the user said and why results were wrong) to the feedback endpoint. If you plan to send any private or sensitive content, restrict or disable automatic feedback reporting. - The API path name (gunPartsSearch) is more specific than the skill description; ask the publisher to clarify what classes of prohibited items the database contains (e.g., weapons/gun parts) to ensure the tool is appropriate for your use. - If you proceed, scope the API key (least privilege), monitor outbound network calls, and request audit/logging or a data-processing agreement from the provider. If you need help verifying the provider, ask the publisher for a canonical homepage, privacy policy, or published API documentation.

Like a lobster shell, security has layers — review code before you run it.

latestvk9710nj4mskdae4gv665m0z1an841gwb
86downloads
0stars
1versions
Updated 3w ago
v1.0.0
MIT-0

Ruiguan Policy Compliance Image Detection

This skill guides you on how to use the Ruiguan policy compliance detection tool to identify potential policy violations in product images. It performs image-based similarity search against a known database of prohibited products.

Core Concepts

Ruiguan Policy Compliance Image Detection is an image-based compliance screening service. Given a product image URL, it searches for visually similar products in a database of known policy-violating items. The tool returns matching violations ranked by visual similarity.

Similarity score (cosine): A value between 0 and 1. Higher values indicate stronger visual resemblance to known violating products. A score close to 1.0 means the product image is nearly identical to a flagged violation.

Parameter Guide

ParameterTypeRequiredDescriptionExample
Image URLimageUrlYesThe URL of the product image to check (max 1000 chars)https://example.com/product.jpg

Key notes:

  • The image URL must be publicly accessible
  • Supported formats include common image types (JPG, PNG, etc.)
  • The URL must not exceed 1000 characters

Response Fields

FieldAPI NameDescription
Total MatchestotalNumber of matching violation records found
Violation ListdataArray of matched violating products
Violation ImagepdImgOssUrlImage URL of the matched violating product
Similarity ScorecosineSimilarity between the input image and the violation (0~1)
Product Title (EN)pdTitleEnglish title of the matched violating product
Product Title (CN)pdTitleCHNCensoredChinese title of the matched violating product
Detection IDdetectIdUnique identifier for this detection session
Token CostcostTokenNumber of tokens consumed by this request

Usage Examples

1. Basic compliance check for a single product image

Check this product image for policy compliance: https://example.com/images/product-123.jpg

2. Batch checking multiple product images

Please scan these product images for potential policy violations:
- https://example.com/images/item-a.jpg
- https://example.com/images/item-b.jpg

3. Pre-listing compliance screening

Before I list this product, can you check if the image triggers any policy flags?
Image: https://example.com/new-product.png

Display Rules

  1. Show results in a clear table: Present each matched violation with its image, similarity score, and product titles
  2. Highlight high-similarity matches: When the cosine score exceeds 0.8, clearly flag the result as a strong match that likely requires attention
  3. Include violation images: When results contain pdImgOssUrl, display the matched violation image so the user can visually compare
  4. Score interpretation: Always explain what the similarity score means -- higher values indicate closer resemblance to known violations
  5. Error handling: When a query fails, explain the issue and suggest checking whether the image URL is valid and publicly accessible
  6. No legal advice: Present detection results factually without providing legal conclusions; remind users to verify with platform policies

Important Limitations

  • Image-only detection: This tool works exclusively with image URLs; it does not analyze text descriptions or product metadata
  • URL accessibility: The image URL must be publicly reachable by the detection service
  • URL length cap: Image URLs must not exceed 1000 characters
  • Similarity-based: Results are based on visual similarity and do not constitute a definitive policy ruling

User Expression & Scenario Quick Reference

Applicable -- Image-based product policy compliance checks:

User SaysScenario
"Check if this product image has compliance risks"Single image compliance check
"Scan my product images for policy violations"Batch compliance screening
"Is this image flagged as a prohibited product"Specific violation inquiry
"Pre-screen my listing images for policy risks"Pre-listing compliance audit
"Find similar violations for this product image"Similarity-based violation search
"这个产品能安全上架吗"合规风险预检
"帮我检测一下这个图片是否违规"单图合规检测

Not applicable -- Needs beyond image-based policy compliance detection:

  • Text-based product compliance analysis
  • General product category classification
  • Intellectual property / trademark infringement
  • Patent or copyright detection (use other Ruiguan skills)

Feedback:

Auto-detect and report feedback via the Feedback API when any of the following apply:

  1. The functionality or purpose described in this skill does not match actual behavior
  2. The skill's results do not match the user's intent
  3. The user expresses dissatisfaction or praise about this skill
  4. Anything you believe could be improved

Call the feedback API as specified in references/api.md. Do not interrupt the user's flow.


For more high-quality, professional cross-border e-commerce skills, set LinkFox Skills.

Comments

Loading comments...