安全扫描
OpenClaw
安全
high confidenceThis is an instruction-only product playbook: it contains guidance and templates, asks for no credentials or installs, and its requested behavior matches its description.
评估建议
This skill appears coherent and low-risk: it's a static playbook with no installs or credential requests. Before installing, consider whether the playbook's templates and recommended outputs align with your organization's processes. If you plan to feed real product metrics when invoking the skill, avoid pasting secrets or sensitive internal URLs into prompts. If you later modify this skill to add integrations (APIs, downloads, or automation), re-evaluate for required credentials, install sources...详细分析 ▾
✓ 用途与能力
The name/description (product strategy, PMF, roadmapping, research, prototyping, competitive analysis, R&D governance) aligns with the SKILL.md and the included full-playbook reference. The skill does not request unrelated binaries, credentials, or config paths.
✓ 指令范围
The runtime instructions tell the agent to act as a product/innovation leader, provide frameworks, and always return a specified output format. It asks the user for missing contextual inputs (product stage, segment, baseline metrics, etc.). It does not instruct the agent to read system files, environment variables, network endpoints, or transmit data outside the agent, so there is no scope creep visible in the provided content.
✓ 安装机制
No install spec and no code files beyond markdown are present. Nothing is downloaded, extracted, or written to disk by the skill itself — this is the lowest-risk pattern for skills.
✓ 凭证需求
The skill declares no required environment variables, no primary credential, and no config paths. The SKILL.md does not reference any secrets or external tokens. Requested information is user-provided contextual data (product stage, metrics), which is proportionate to the skill's purpose.
✓ 持久化与权限
always is false and the skill is user-invocable. disable-model-invocation is false (normal), meaning the agent may call it autonomously if enabled — this is expected platform behavior and is not combined here with any broad privileges, credential access, or modification of other skills.
安全有层次,运行前请审查代码。
运行时依赖
无特殊依赖
版本
latestv1.0.02026/3/7
Initial public release from OpenCTO skills pack
● 无害
安装命令
点击复制官方npx clawhub@latest install product-innovation-playbook
镜像加速npx clawhub@latest install product-innovation-playbook --registry https://cn.longxiaskill.com