叉车配件直播运营助手

PassAudited by ClawScan on May 17, 2026.

Overview

This is an instruction-only livestream sales assistant with no code or credentials, but users should verify sales claims and protect customer inquiry details.

This skill appears benign and instruction-only. Before installing, plan to verify all product claims, prices, warranties, promotions, inventory, and fitment statements, and avoid putting unnecessary customer personal or business data into the agent.

Findings (3)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

If used verbatim in a livestream, the user could make unverified commercial promises about price, warranty, or product performance.

Why it was flagged

The reference script contains concrete price and warranty claims, while SKILL.md instructs that price, stock, warranty, shipping, and fitment information require human confirmation.

Skill content
质保期限 | 6个月/3000小时 ... 单价 | ¥380-680 ... “非人为鼓包、脱层,6个月内免费换新,运费我们出!”
Recommendation

Treat the sales scripts as editable templates and confirm all price, warranty, inventory, shipping, and fitment details before publishing or telling customers.

What this means

Customer contact and business information could be exposed if pasted into shared chats, logs, or documents without consent or access controls.

Why it was flagged

The inquiry form is purpose-aligned for customer follow-up but encourages entering personal, business, payment, and transaction details into generated records or agent context.

Skill content
联系电话 | ______ ... 公司/车队名称 | ______ ... 付款方式 | □微信/支付宝 □对公转账 □货到付款 ... 成交金额 | 付款状态
Recommendation

Collect only necessary customer information, avoid entering sensitive details unless needed, and store generated inquiry records in a controlled location.

What this means

Battery livestream output may rely on the general instructions or risk guide rather than the referenced complete script.

Why it was flagged

SKILL.md references a live-script file for battery content, but the provided file manifest does not include references/live-scripts/battery.md. This is an incomplete-resource issue, not evidence of malicious behavior.

Skill content
`battery.md` - 叉车电瓶完整话术包(11大模块)
Recommendation

If battery scripts are important, ask the publisher to include the missing referenced file or verify battery-related outputs manually.