Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Taobao Ecommerce System

v1.0.0

2026 无货源电商运营系统 - 智能选品、标准化上架、万相台测款、订单自动化、智能客服

1· 236·1 current·1 all-time

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for guowaa223/taobao-ecommerce-system.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "Taobao Ecommerce System" (guowaa223/taobao-ecommerce-system) from ClawHub.
Skill page: https://clawhub.ai/guowaa223/taobao-ecommerce-system
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Required binaries: python3
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install taobao-ecommerce-system

ClawHub CLI

Package manager switcher

npx clawhub@latest install taobao-ecommerce-system
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
Name/description describe a full e‑commerce system (API integrations, automatic push to 1688, monitoring, etc.). The manifest requests only python3 and lists Python deps (requests, pandas, Pillow) which is reasonable for this purpose. However, the included main script does not implement any network/API calls — it only prints simulated flows — so the delivered capability is a stub/demo rather than the full integration the docs promise.
Instruction Scope
SKILL.md and README instruct the agent to run the script with various commands; that is consistent with an instruction-only skill. The docs promise 'official API' usage and 'only manual confirmation' for high-risk ops, but the runtime instructions do not require reading unrelated system files. The script does call load_dotenv(), creates a logs folder, and reads LOG_LEVEL from environment — so it will read environment/.env if present, which is not declared in requires.env.
Install Mechanism
No install spec is present (instruction-only with a Python script). That is low risk — nothing is automatically downloaded or executed beyond the local Python script and standard pip-installed dependencies listed in requirements.txt.
!
Credentials
requires.env lists none, but requirements.txt includes python-dotenv and the script calls load_dotenv(); README references a .env for API keys. The skill therefore may read environment variables or a .env file (potentially API keys) without declaring them as required. This mismatch means a user might unknowingly expose credentials if they run the skill with a populated .env.
Persistence & Privilege
The skill is not always-enabled; user-invocable is true and autonomous invocation is allowed by default. It writes logs under ./logs but does not modify other skills or system-wide settings. No elevated persistence or privileged actions are requested.
What to consider before installing
This package looks like a documented demo: the README/SKILL.md promise live Taobao/1688 API operations, but the included Python script only prints simulated outputs and does not call external APIs. Before installing or running with real credentials: 1) Inspect the code paths that would contact APIs (search for requests, urllib, or SDK usage) and confirm where endpoints/keys are used. 2) Do not place real API keys/secrets in a .env in the skill folder until you confirm the code's network behavior. 3) Run the script in a sandboxed environment (no real credentials, limited network) to observe actual calls. 4) If you expect real integration, request a version that clearly implements authenticated API calls and documents exactly which env vars are required. The current mismatch (docs vs. implementation + undeclared .env usage) is the reason for a cautious classification.

Like a lobster shell, security has layers — review code before you run it.

Runtime requirements

🛍️ Clawdis
OSWindows
Binspython3
latestvk972p6rm9z42r2cvzmpxvnbrgx83x4j0
236downloads
1stars
1versions
Updated 4w ago
v1.0.0
MIT-0
Windows

2026 无货源电商运营系统

⚠️ 重要安全声明

本系统严格遵守:

  1. 仅人工触发 - 所有操作需人工确认
  2. 官方 API - 仅通过淘宝/1688 官方 API
  3. 合规第一 - 100% 符合 2026 淘宝最新规则
  4. 数据驱动 - 用数据决策,不用感觉

🎯 核心功能模块

1. 智能选品系统(乘法电商·精细化选品 2026 版)

功能:

  • ✅ 网商园/1688批量采集
  • ✅ 淘宝同款数据查询
  • ✅ 5 个数据指标自动筛选
  • ✅ 利润精算(含所有成本)
  • ✅ 侵权风险检测
  • ✅ 档口联系方式提取

选品标准:

1. 淘宝同款数 < 5000(竞争小)
2. 头部垄断度 < 60%(垄断低)
3. 新品机会 > 15%(新品有机会)
4. 价格空间 > 100%(有利润空间)
5. 搜索趋势上升(趋势向上)
6. 净利率 > 20%(可做)

2. 标准化上架系统

功能:

  • ✅ 标题优化(3 步法)
  • ✅ 主图处理(去水印、调色)
  • ✅ 详情页模板(5 个可复用)
  • ✅ 价格设置(保本计算)
  • ✅ 属性填写(合规检测)

3. 智能推广系统(万相台无界·4+2 模型)

功能:

  • ✅ 4 个拉新计划自动搭建
  • ✅ 2 个收割计划自动开启
  • ✅ 实时数据监控
  • ✅ 达标线自动判断
  • ✅ 止损规则自动执行

测款标准(7 天周期):

✅ 爆款潜力:
- 点击率 > 3.5%
- 收藏加购率 > 15%
- 转化率 > 3.5%
- ROI > 2.5

❌ 停止推广:
- 点击率 < 2.5%
- 收藏加购率 < 10%
- 转化率 < 2%
- ROI < 1.5

4. 订单自动化系统

功能:

  • ✅ 1688 推单 API 对接
  • ✅ 网商园下单辅助
  • ✅ 自动回填单号
  • ✅ 物流实时监控
  • ✅ 异常自动预警

5. 智能客服系统

功能:

  • ✅ 快捷回复话术库
  • ✅ 意图自动识别
  • ✅ 售后自动分类
  • ✅ 高风险预警
  • ✅ 差评挽回话术

📋 使用命令

智能选品

python scripts/ecommerce_main.py select-product --source "网商园链接" --batch

标准化上架

python scripts/ecommerce_main.py upload-product --product-id KZ20260326

推广监控

python scripts/ecommerce_main.py marketing-monitor --plan-id 12345

订单处理

python scripts/ecommerce_main.py process-orders --auto

客服辅助

python scripts/ecommerce_main.py cs-helper --start

🛡️ 安全与合规

本系统不会:

  • ❌ 自动上架发布(仅生成草稿)
  • ❌ 自动调整投流(仅生成建议)
  • ❌ 自动处理大额退款(仅 3 类低风险)
  • ❌ 超范围调用 API
  • ❌ 抓取非公开数据

本系统仅支持:

  • ✅ 生成方案/建议/报告
  • ✅ 人工确认后执行
  • ✅ 官方 API 操作
  • ✅ 合规风控预警

🛍️ 2026 无货源电商运营系统 — 数据驱动,合规第一

Comments

Loading comments...