安全扫描
OpenClaw
安全
medium confidence该技能为仅提供指令的社交媒体营销规划工具,其要求和指令一般与其目的相符,但在安装或执行安装命令前,应谨慎检查少数来源和安装说明。
评估建议
该技能看似如其所述:一位社交媒体策略顾问,仅提供指令,不会访问您的系统或凭证。执行 SKILL.md 中的 'npx' 安装示例前,请验证 nexscope-ai/eCommerce-Skills 包或 GitHub 仓库(检查其代码和维护者)。不要运行不信任的任意 npx/npm 命令。如果计划连接账户(Instagram、TikTok、Shopify 等),仅提供可信的 API 密钥或令牌,并考虑限制技能的自主调用或先审查其代码。如果来源重要,请要求发布者提供主页或源代码仓库,并在安装前审查该仓库。...详细分析 ▾
✓ 用途与能力
Name, description, and SKILL.md capabilities align: planning social media strategy, content calendars, platform recommendations, and social-commerce guidance are coherent with the skill's stated purpose. The SKILL.md references Nexscope and related GitHub repos even though the registry entry has no homepage/source; this is a provenance mismatch worth noting but not necessarily malicious.
✓ 指令范围
Runtime instructions describe collecting user-provided marketing details and asking one structured follow-up; they do not instruct reading system files, environment variables, or accessing unrelated data. The doc mentions 'research and analyze' without specifying data sources — this could imply using web resources or internal heuristics but is not itself an instruction to exfiltrate or access secrets.
ℹ 安装机制
The skill is instruction-only (no install spec in registry), which is low-risk. However, SKILL.md includes an example install command using 'npx skills add nexscope-ai/eCommerce-Skills ...' — running that would download and execute third-party code. Because the registry metadata does not include an install spec or homepage, verify the referenced package/repo before running npx or any external installer.
✓ 凭证需求
No required environment variables, credentials, or config paths are declared or referenced. That is proportionate for a planning/advice skill; it does not request unrelated secrets or system access.
✓ 持久化与权限
always is false and the skill does not request special persistence or modify other skills. The default ability for the agent to invoke the skill autonomously is normal; there are no extra privileges requested.
安全有层次,运行前请审查代码。
运行时依赖
无特殊依赖
版本
latestv1.0.02026/3/26
Beta 版发布 — 为电商 AI 代理提供的功能性技能。由 Nexscope 构建。
● 无害
安装命令 点击复制
官方npx clawhub@latest install ecommerce-social-media-marketing
镜像加速npx clawhub@latest install ecommerce-social-media-marketing --registry https://cn.clawhub-mirror.com
技能文档
为电商品牌规划社交媒体营销策略,包括内容日历、平台选择、发布时间表、互动策略和社交商务等。...
# 安装和使用(保留原文,假设这里有命令行指令)
npx @nexscope-ai/eCommerce-Skills...
# 代码示例(保留原文,假设这里有代码块)
// 示例代码
注意: 以上 --- 之下的内容保持原文未翻译,仅示例。实际内容应根据原始 SKILL.md 文件填充。
数据来源:ClawHub ↗ · 中文优化:龙虾技能库
OpenClaw 技能定制 / 插件定制 / 私有工作流定制
免费技能或插件可能存在安全风险,如需更匹配、更安全的方案,建议联系付费定制