Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Shopify Fulfillment Strategy

v1.0.0

Choose and optimize between 3PL, in-house, and hybrid fulfillment models for Shopify stores based on volume, cost, and growth stage. Triggers: fulfillment st...

0· 101·0 current·0 all-time

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for mguozhen/shopify-fulfillment-strategy.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "Shopify Fulfillment Strategy" (mguozhen/shopify-fulfillment-strategy) from ClawHub.
Skill page: https://clawhub.ai/mguozhen/shopify-fulfillment-strategy
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install shopify-fulfillment-strategy

ClawHub CLI

Package manager switcher

npx clawhub@latest install shopify-fulfillment-strategy
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
!
Purpose & Capability
The skill name, description, SKILL.md, and analyze.sh all focus on Shopify fulfillment strategy and are internally consistent. However, the analyze.sh script invokes a local 'openclaw' CLI (openclaw agent ...) even though the skill declares no required binaries. That undeclared dependency is an inconsistency: a runtime component is required but not documented in the metadata.
Instruction Scope
The SKILL.md and the script stay within the stated scope (generate a fulfillment strategy from user-supplied input). The script only uses the provided INPUT and constructs a prompt. It does, however, pass that prompt to a local agent process (openclaw agent --local --message ...) which may cause the agent to read local config or make network requests depending on the local agent's behavior — the skill's instructions do not document that side effect.
Install Mechanism
There is no install spec (instruction-only + a helper script). Nothing is downloaded or written to disk by an installer. This is the lower-risk pattern, aside from the script's invocation of a local CLI.
Credentials
The skill does not request environment variables, credentials, or config paths. The script does not attempt to read environment secrets. That is proportionate for a strategy/report generator. Users should avoid providing sensitive credentials as the INPUT parameter.
Persistence & Privilege
The skill is not always-enabled and does not request elevated persistence. It does invoke a local agent process when run; autonomous invocation is allowed by platform defaults but is not specially elevated here.
What to consider before installing
This skill appears to do what it says (produce a Shopify fulfillment strategy), but the included analyze.sh calls a local 'openclaw agent' binary that is not declared in the skill metadata. Before installing or running: 1) Verify you have (and trust) the openclaw CLI on the host — the script will execute it and that local agent could read local configs or make network calls depending on its implementation. 2) Do not pass store credentials, API keys, or other secrets as the INPUT argument; the script embeds INPUT into a prompt sent to the agent. 3) Inspect the repository/homepage (https://github.com/mguozhen/shopify-fulfillment-strategy) to confirm origin and review any additional code. 4) If you plan to run the script, run it in an isolated environment or sandbox first. If the publisher can clarify why the openclaw binary is not declared, that would reduce the remaining concern.

Like a lobster shell, security has layers — review code before you run it.

latestvk97ecppsf2g34f276bc35c571583nx60
101downloads
0stars
1versions
Updated 1mo ago
v1.0.0
MIT-0

Shopify Fulfillment Strategy Optimizer

A complete fulfillment model evaluation and optimization guide for Shopify merchants. This skill analyzes the trade-offs between in-house, 3PL, and hybrid fulfillment to recommend the right model for your order volume, SKU complexity, growth stage, and customer expectations.

Usage

fulfillment strategy for: <store niche or URL>
3PL vs in-house: <current order volume>
outsource fulfillment: <store description>
choose fulfillment model: <order volume and SKUs>

What You Get

  1. Fulfillment Model Comparison — In-house vs 3PL vs hybrid cost-benefit analysis
  2. When to Switch to 3PL — Volume and complexity thresholds for outsourcing
  3. 3PL Selection Framework — How to evaluate and choose the right partner
  4. 3PL Contract Negotiation — Key terms, rates, and SLA requirements
  5. Onboarding & Integration — How to migrate to a new fulfillment provider
  6. Performance Monitoring — 3PL KPIs and accountability frameworks
  7. Scaling Fulfillment — Planning capacity for growth and peak seasons

Comments

Loading comments...