Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Shopify Store

v1.0.1

提供Shopify建店指导、套餐价格、主题推荐、支付设置及数据分析,助力快速搭建和管理在线商店。

0· 77·1 current·1 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
high confidence
!
Purpose & Capability
The public description claims active guidance for building Shopify stores, pricing/packages, theme recommendations, payment setup and data analysis. However the skill contains only a short, generic 'knowledge card' template with no operational procedures, API calls, or steps to perform these tasks. That mismatch is inconsistent: a real Shopify integration would normally require APIs, credentials, or at least detailed runbook text.
!
Instruction Scope
SKILL.md only instructs the agent to present a brief knowledge card when the user searches for 'shopify-store'. It does not include commands, file access, API endpoints, or any guidance for performing store setup, configuring payments, recommending themes, or analyzing store data. The instructions are therefore much narrower than the described capabilities.
Install Mechanism
No install spec and no code files are present. This lowers risk because nothing is written to disk and there are no third-party packages or downloads.
!
Credentials
The skill declares no environment variables or credentials. For the advertised features (Shopify setup, payment configuration, analytics), one would normally expect declared credentials (Shopify API key, access token, or payment provider keys). The absence of any declared env vars is inconsistent with the claimed capabilities.
Persistence & Privilege
Defaults are used (not always:true). The skill is user-invocable and may be invoked by the agent normally; there is no indication it requests elevated or persistent privileges.
What to consider before installing
This skill appears to be a stub or placeholder rather than a working Shopify integration. Do not assume it will perform store setup, change payment settings, or access analytics. If you need automation or access to a real Shopify store, look for a skill that explicitly documents the necessary API endpoints and required credentials (e.g., SHOPIFY_API_KEY, STORE_ACCESS_TOKEN), or contact the skill author for a full implementation. Because this skill currently requires no credentials and has no install, it's low-risk to try, but it will likely not deliver the promised operational features.

Like a lobster shell, security has layers — review code before you run it.

latestvk9785vjzd5zznfv4zcbbkz28ds84xnjk

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Comments