Tender Knowledge Framework
v1.0.0构建全面的招投标知识体系,涵盖文件解读、投标编制、评标分析、合同风险及行业案例,助力提升中标率。
⭐ 0· 31·1 current·1 all-time
by@ylbwjf
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Benign
high confidencePurpose & Capability
Name/description (招投标知识体系) match the SKILL.md and included knowledge files. The skill requests no credentials, binaries, or installs and the content is focused on document reading, bid preparation, scoring and contract analysis — all coherent with the stated purpose.
Instruction Scope
Instructions direct the agent to actively search the Internet (official sites, platforms, social media, video sources) and produce periodic reports every 4 hours; this is reasonable for a learning/curation skill but gives the agent broad discretion to fetch external web content. The SKILL.md does not instruct reading local system secrets or unrelated files, but does instruct writing notes to paths like memory/tender-learning and tender-knowledge-framework/knowledge which is expected for a knowledge skill.
Install Mechanism
No install spec and no code files — instruction-only. Nothing is downloaded or written during install, which is the lowest-risk install model.
Credentials
The skill requires no environment variables, credentials, or config paths. There are no disproportionate secret requests.
Persistence & Privilege
always is false and the skill does not request persistent or elevated privileges or modifications to other skills. It does describe periodic reporting times, but since it has no special 'always' privilege this is an instruction not an enforced daemon.
Assessment
This skill is internally consistent and appears benign, but consider these practical points before enabling it: (1) it instructs the agent to actively fetch and summarize public web content (including social platforms and videos) — confirm your agent has appropriate network access and that web scraping complies with terms of service; (2) it will write learning notes and report files under memory/tender-learning and tender-knowledge-framework — if you have sensitive data in the agent environment, ensure the agent's file permissions and storage policies are acceptable; (3) review whether you want the agent to run periodic learning/reporting when invoked autonomously (the skill itself is not forced always-on, but autonomous invocation may trigger the described behavior); (4) if you need stricter controls, restrict network access or require explicit user prompts before web scraping or publishing reports.Like a lobster shell, security has layers — review code before you run it.
latestvk9759tba7817ytm8cvvpp1q0wd844qxw
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
