← 返回 Skills 市场
mguozhen

Shopify Ambassador Program

作者 mguozhen · GitHub ↗ · v1.0.0 · MIT-0
cross-platform ⚠ suspicious
113
总下载
0
收藏
0
当前安装
1
版本数
在 OpenClaw 中安装
/install shopify-ambassador-program
功能描述
Design and launch a brand ambassador program for Shopify stores to build a network of authentic advocates who drive sales and awareness. Triggers: ambassador...
安全使用建议
This skill appears to legitimately produce a brand ambassador program blueprint, but the included analyze.sh will run a local 'openclaw' CLI (openclaw agent --local ...) when executed. The manifest does not declare this required binary, so: (1) don't run the script unless you know and trust the openclaw binary on your system; (2) inspect the script (it's plain text) and confirm you are comfortable with it spawning a child process; (3) if you only want the strategy output, ask the author to either (a) include the generated content directly in SKILL.md, (b) update metadata to declare 'openclaw' as a required binary, or (c) remove the nested agent invocation and provide a pure instruction-only version; (4) if you run it, prefer a sandboxed environment and ensure no sensitive credentials are present in that environment.
功能分析
Type: OpenClaw Skill Name: shopify-ambassador-program Version: 1.0.0 The skill bundle is classified as suspicious due to a prompt injection vulnerability in analyze.sh. The script takes raw user input and directly incorporates it into a complex prompt for a local OpenClaw agent session without any sanitization or filtering. While the stated purpose of designing Shopify ambassador programs is benign and aligned with the instructions in SKILL.md, this lack of input handling allows for potential agent hijacking. No evidence of intentional malice, such as data exfiltration or backdoors, was found in the code logic.
能力评估
Purpose & Capability
The skill's name, description, and SKILL.md content are coherent with a marketing/strategy helper for Shopify merchants. However, the included analyze.sh invokes a local 'openclaw' CLI which is not listed in the skill's required binaries; requiring a local agent binary to generate the output is unexpected for a content/design skill.
Instruction Scope
SKILL.md itself describes marketing deliverables and does not request secrets or system files. The shipped analyze.sh constructs a prompt and runs 'openclaw agent --local --message ... --session ...', meaning executing the script will spawn a nested local agent process. The script does not read environment variables or external files, and it does not send data to remote endpoints directly, but it does rely on a local binary and will execute a child process.
Install Mechanism
No install spec is present (instruction-only plus a script). Nothing in the manifest downloads or extracts remote code. The only on-disk file is analyze.sh which is readable; risk comes from executing it, not from a remote install step.
Credentials
The skill declares no required environment variables, credentials, or config paths. The script does not reference secrets or external service tokens. That is proportionate to the stated purpose.
Persistence & Privilege
always is false and there are no indications the skill requests persistent system privileges or modifies other skills/config. The only noteworthy behavior is that the script runs a local agent process, but it does not enable permanent presence.
如何使用
  1. 确保已安装 OpenClaw(本地或 Docker 部署)
  2. 在对话框中输入安装命令:/install shopify-ambassador-program
  3. 安装完成后,直接呼叫该 Skill 的名称或使用 /shopify-ambassador-program 触发
  4. 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.0
Initial release providing a comprehensive brand ambassador program toolkit for Shopify stores: - Program architecture with tiers, requirements, and identity. - Recruitment, onboarding, and activation systems for ambassadors. - Content frameworks, incentive structures, and performance measurement. - Designed for building, launching, and managing authentic advocate networks.
元数据
Slug shopify-ambassador-program
版本 1.0.0
许可证 MIT-0
累计安装 0
当前安装数 0
历史版本数 1
常见问题

Shopify Ambassador Program 是什么?

Design and launch a brand ambassador program for Shopify stores to build a network of authentic advocates who drive sales and awareness. Triggers: ambassador... 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 113 次。

如何安装 Shopify Ambassador Program?

在 OpenClaw 或 Claude Code 对话框中运行命令「/install shopify-ambassador-program」即可一键安装,无需额外配置。

Shopify Ambassador Program 是免费的吗?

是的,Shopify Ambassador Program 完全免费,采用 MIT-0 许可证,可自由下载、安装和使用。

Shopify Ambassador Program 支持哪些平台?

Shopify Ambassador Program 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。

谁开发了 Shopify Ambassador Program?

由 mguozhen(@mguozhen)开发并维护,当前版本 v1.0.0。

💬 留言讨论