Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Taobao Automation

v1.0.0

实现淘宝店铺运营选品分析、标题优化、数据监控、竞品监控及营销文案自动生成与推送。

0· 500·1 current·1 all-time

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for guowaa223/taobao-automation.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "Taobao Automation" (guowaa223/taobao-automation) from ClawHub.
Skill page: https://clawhub.ai/guowaa223/taobao-automation
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install taobao-automation

ClawHub CLI

Package manager switcher

npx clawhub@latest install taobao-automation
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
!
Purpose & Capability
The skill claims integration with Feishu/WeChat (for messages and calendar), Cron scheduling, TTS, Canvas image generation, and web scraping of Taobao/competitors — but the registry metadata requests no environment variables, no credentials, and provides no install mechanism. Integrations like Feishu and push notifications normally require API keys/app credentials; scraping Taobao at scale typically needs authenticated cookies, proxies, or rate-limit handling. The requested manifest is missing expected capabilities and artifacts for the stated purpose.
!
Instruction Scope
SKILL.md instructs the agent to perform web_search/web_fetch, run periodic cron-like tasks, push data to Feishu/WeChat, perform TTS and generate canvases. It gives no guidance on where to store or how to obtain API credentials, how to set up cron/background jobs, nor does it limit what pages or data may be collected. The instructions therefore overreach: they direct data collection and external transmission but do not specify required auth, endpoints, or safeguards.
Install Mechanism
This is instruction-only (no install spec, no code files), which minimizes on-disk risk but is also insufficient for implementing cron jobs, TTS engines, or canvas libraries. Without an install step, it's unclear how the skill expects scheduled tasks or TTS/Canvas to be provisioned on the host; this is an implementation gap rather than direct malware evidence.
!
Credentials
The skill declares zero required env vars / credentials despite referencing services that require secrets (Feishu/WeChat API tokens, TTS service keys, possibly Taobao session cookies or API credentials). That mismatch is disproportionate and suggests either the manifest is incomplete or the skill would attempt to use ambient credentials unexpectedly.
Persistence & Privilege
always is false and there is no request to modify other skills or system-wide settings. However, the skill expects scheduled/automated behavior (cron jobs and periodic scraping); since no installation mechanism is declared, it's unclear how scheduling is intended to be established or authorized. Autonomous invocation is allowed by default (not flagged alone) but combined with the missing credential/setup details increases risk.
What to consider before installing
This skill's description and runtime instructions expect integrations (Feishu/WeChat pushes), scheduled background jobs, TTS, and web scraping, but the package declares no credentials, no install steps, and no config paths. Before installing or enabling it, ask the author to: (1) list exactly which credentials it needs (Feishu app ID/secret, WeChat tokens, TTS API keys, Taobao credentials or cookie management) and how they will be provided/stored; (2) explain how cron/scheduling is implemented and authorized; (3) provide concrete endpoints and rate-limit/backoff behavior for scraping and a statement on compliance with Taobao's terms; (4) supply an install spec or code for review so you can verify it won't exfiltrate ambient credentials. If the author cannot supply credentials and an install plan, consider the skill unsafe to enable for autonomous runs — at minimum restrict it to user-invoked mode and require explicit, per-run consent and manual credential input.

Like a lobster shell, security has layers — review code before you run it.

latestvk97fnm67phcp3tqnxnv1makd0183wt4j
500downloads
0stars
1versions
Updated 4w ago
v1.0.0
MIT-0

淘宝店铺运营自动化技能

技能名称: taobao-automation 版本: 1.0.0 功能: 淘宝店铺运营全流程自动化 适用: 电商运营、店铺管理、数据监控


概述

本技能将 OpenClaw 能力与淘宝店铺运营结合,实现:

  • 选品分析自动化
  • 数据监控定时提醒
  • 竞品分析
  • 营销文案生成
  • 运营报告自动推送

能力映射

1. 选品分析 (Web Search + Fetch)

用户: "帮我分析茶叶类目"
↓
OpenClaw:
  1. web_search: 搜索淘宝茶叶竞品数据
  2. web_fetch: 抓取分析页面
  3. 生成选品建议报告

2. 标题优化助手 (AI分析)

用户: "帮我优化连衣裙标题"
↓
OpenClaw:
  1. 分析产品核心卖点
  2. 生成关键词组合
  3. 建议标题模板

3. 数据监控 (Cron + Feishu通知)

定时任务:
  1. 每日9:00 查询店铺关键指标
  2. 生成数据简报
  3. 推送到飞书/微信

4. 竞品监控 (Web自动抓取)

用户: "监控竞店价格"
↓
OpenClaw:
  1. 定期抓取竞品页面
  2. 对比价格/销量变化
  3. 异常预警

5. 营销文案生成 (TTS + Canvas)

用户: "生成产品推广语音"
↓
OpenClaw:
  1. 分析产品卖点
  2. 生成营销文案
  3. TTS语音输出

6. 运营日程管理 (Feishu Calendar)

功能:
  1. 大促时间节点提醒
  2. 上新计划日历
  3. 推广预算提醒

自动化场景

场景1: 每日数据播报

# Cron: 每天 09:00, 18:00
# 动作:
#   1. 获取昨日核心指标
#   2. 对比数据变化
#   3. 推送飞书消息

场景2: 竞品监控

# Cron: 每4小时
# 动作:
#   1. 抓取竞品价格/销量
#   2. 记录变化趋势
#   3. 异常时预警

场景3: 标题优化

# 用户触发
# 动作:
#   1. 分析产品属性
#   2. 推荐关键词组合
#   3. 生成3个标题选项

使用命令

功能命令/触发
选品分析"分析[品类]市场"
标题优化"优化[产品]标题"
数据报告"生成昨日数据报告"
竞品监控"监控[竞店名]"
营销文案"生成[产品]推广文案"
设置提醒"每天[时间]提醒数据"

技术栈

  • Web: 搜索、爬取竞品数据
  • Feishu API: 消息推送、日历提醒
  • Cron: 定时任务
  • TTS: 语音合成
  • Canvas: 图片/海报生成

示例对话

用户: 帮我分析茶叶店选品

OpenClaw:

📊 茶叶类目分析报告

## 市场规模
- 月销: 50万+ 件
- 均价: 89-168元

## 热门品类
1. 红茶礼盒 (送礼场景)
2. 绿茶新茶 (季节性)
3. 普洱茶 (收藏属性)

## 竞争分析
- Top10店铺: 专业茶企旗舰店
- 差异化机会: 年轻化包装、私域流量

## 建议
- 主推: 轻便装口粮茶
- 定价: 59-99元区间
- 卖点: 便捷冲泡、健康天然

注意事项

  1. 合规性: 遵守淘宝平台规则,不采集敏感数据
  2. 频率限制: 合理控制API调用频率
  3. 数据准确: 第三方数据仅供参考

更新日志

  • 2026-03-24: v1.0.0 初始版本

Comments

Loading comments...