淘宝/京东/拼多多/全网商品检索比价

ReviewAudited by ClawScan on May 10, 2026.

Overview

The skill mostly matches its price-comparison purpose, but its purchase-link generator uses a third-party service with embedded identifiers and an invite/share code that is not clearly disclosed.

Install only if you are comfortable with searches and link generation going through maishou88.com. Treat returned links as potentially share/referral-attributed, verify prices and sellers before buying, and avoid sensitive shopping searches unless the skill adds clearer privacy and referral disclosures.

Findings (5)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

Clicking or buying through returned links may be attributed to an embedded invite/share identifier rather than being a neutral direct link.

Why it was flagged

The link command creates target/share URLs using a default invite code. SKILL.md presents these simply as purchase links, so any referral, attribution, or share-link behavior is not clearly disclosed to the user.

Skill content
url = 'https://msapi.maishou88.com/api/v1/share/getTargetUrl' ... inviteCode = os.environ.get("INVITE_CODE", "46608499") ... "isShare": "1"
Recommendation

Prominently disclose the invite/share-link behavior, label any affiliate or referral links, and let users opt out or provide their own code.

What this means

Requests may be associated with a shared embedded service identity whose account context and permissions are opaque to the user.

Why it was flagged

The script sends a built-in openid service identifier when the user has not configured one, even though the registry declares no required credentials.

Skill content
openid = os.environ.get("OPENID", "dfe8842aaec8323c02dd534328b262c5") ... 'openid': openid
Recommendation

Document the identifier model clearly, declare optional OPENID/INVITE_CODE configuration, and avoid hidden shared identities where possible.

What this means

The third-party service can see the products the user searches for and the items selected for link generation.

Why it was flagged

User search terms and platform selections are sent to an external provider API. This is purpose-aligned, but it is an external data boundary.

Skill content
url = 'https://appapi.maishou88.com/api/v1/homepage/searchList' ... data = { ... 'keyword': keyword, ... 'sourceType': str(source_type) }
Recommendation

Add a clear privacy notice for maishou88.com API use and avoid sending sensitive shopping queries unless the user is comfortable with that.

What this means

The script can make network requests and return purchase links, but the documented workflow keeps the final link-fetching step user-directed.

Why it was flagged

The skill instructs the agent to run a local script with user-provided product terms, but it also explicitly requires waiting for user selection before fetching links.

Skill content
python3 scripts/price.py search --keyword "关键字" --sourceType 0 --pages 1 --format csv ... 然后 **停止并等待用户输入**,不要自动进入下一步。
Recommendation

Keep the explicit user-selection checkpoint and use argument-safe command invocation when passing user-provided keywords.

What this means

It is harder to verify the exact package version and upstream source of the reviewed skill.

Why it was flagged

The registry metadata lacks source/homepage provenance, and the provided SKILL.md/_meta.json artifacts identify version 1.0.3 rather than 1.0.4.

Skill content
Source: unknown; Homepage: none; Version: 1.0.4
Recommendation

Publish a clear source/homepage reference and align the registry, SKILL.md, and _meta.json version numbers.