Back to skill
Skillv1.0.2
VirusTotal security
淘宝/京东/拼多多优惠查询、产品比价 · External malware reputation and Code Insight signals for this exact artifact hash.
Scanner verdict
ReviewApr 17, 2026, 6:11 AM
- Hash
- 346a029d58b0dedddca3ce7111b8c6ac92a514c6b0f52b97dbfe3597d9354dd3
- Source
- palm
- Verdict
- suspicious
- Code Insight
- Type: OpenClaw Skill Name: pricecompare Version: 1.0.2 The skill acts as a proxy for a third-party shopping assistant API (op.squirrel2.cn), sending user messages and search queries to this external endpoint. The SKILL.md file contains forceful instructions directed at the AI agent, commanding it to return the code's output verbatim and prohibiting any modification or reformatting; this is a prompt-injection-style technique often used to ensure the delivery of affiliate links or to bypass the agent's natural output processing. While the behavior aligns with the stated purpose of a shopping assistant, the combination of mandatory pass-through instructions and the transmission of user data to a third-party server presents a significant privacy risk and potential for delivering untrusted content.
- External report
- View on VirusTotal
