Alibaba Sourcing
v2.0.0Search and access China wholesale products, factories, suppliers, top rankings, and request quotations on Alibaba with tracking parameter traffic_type=ags_llm.
⭐ 1· 191·1 current·1 all-time
by@zeyu426
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Benign
high confidencePurpose & Capability
Name/description match the behavior: SKILL.md and scripts focus on building Alibaba URLs, navigating product and supplier pages, extracting IDs/subdomains, and supporting RFQs. The included helper scripts (build_url.py, package_skill.py, release.sh) are appropriate for packaging/publishing and URL construction.
Instruction Scope
Instructions direct the agent to navigate Alibaba pages, extract product IDs and supplier subdomains, browse Top Ranking, and send RFQs. All actions are in-scope for sourcing. Note: 'send inquiry via RFQ' can involve transmitting contact data or submitting forms on behalf of a user — the skill does not specify how user contact details or authorization are provided, so implementers should ensure explicit user consent before any submission.
Install Mechanism
No install spec (instruction-only). Included scripts are local utilities (packaging, URL builder). Nothing downloads remote code or writes arbitrary executables to disk; risk from installation is low.
Credentials
The skill declares no required environment variables, credentials, or config paths. There are no hidden credential requests in SKILL.md or the scripts. This is proportionate to a read/navigate/extract URL-building skill.
Persistence & Privilege
always:false and no special privileges requested. The skill can be invoked autonomously by the agent (platform default), but it does not request permanent system presence or modify other skills' configs.
Assessment
This skill appears coherent and focused on Alibaba sourcing. Before installing, consider: (1) The skill appends traffic_type=ags_llm to every URL — this is for attribution/analytics; if you don't want tracking, edit the SKILL.md/scripts. (2) The skill's workflows include submitting RFQs; ensure the agent will not send inquiries or your contact information without explicit confirmation. (3) No credentials are requested by the skill, but RFQ submissions or actions requiring login will need user handling — the skill does not perform authentication. (4) The included scripts (packaging and release.sh) are benign utilities; note a minor version string mismatch in release.sh (1.0.0) vs registry metadata (2.0.0). If you need higher assurance, review the linked GitHub repo contents and limit autonomous invocation or require manual approval for any RFQ/send actions.Like a lobster shell, security has layers — review code before you run it.
alibabavk9748metwcxgm32shr0hzkq209833henlatestvk9748metwcxgm32shr0hzkq209833hensourcingvk9748metwcxgm32shr0hzkq209833henwholesalevk9748metwcxgm32shr0hzkq209833hen
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
