← 返回 Skills 市场
东南亚市场政策查询Skill
作者
yezhaowang888-stack
· GitHub ↗
· v1.0.1
· MIT-0
115
总下载
0
收藏
1
当前安装
2
版本数
在 OpenClaw 中安装
/install southeast-asia-policy-query
功能描述
基于DeepSeek v4的智能系统,已通过ClawHub安全审计
安全使用建议
This package appears to be a templated or partial implementation: docs claim live DeepSeek API integration, scraping and cron-based monitoring and request API keys, but the included JS is a local dummy data generator that never uses network or the listed dependencies. Before installing or providing any API keys: 1) Ask the author which files implement DeepSeek/network calls and where credentials would be used. 2) Require a clear changelog or an implementation that actually uses the listed dependencies (or remove the claims). 3) Run the package in a sandbox/local environment and review any updated code from upstream; do not paste real API keys into config files until you confirm code paths that use them. 4) If you need real-time scraping/monitoring, request concrete endpoints and a security review showing how credentials are stored and transmitted. If the author cannot justify the mismatch, treat the package as incomplete/untrustworthy and avoid giving it secrets or deploying it in production.
功能分析
Type: OpenClaw Skill
Name: southeast-asia-policy-query
Version: 1.0.1
The skill bundle exhibits suspicious characteristics primarily through deceptive 'trust-building' claims and a significant discrepancy between its documentation and actual code. The SKILL.md and README.md claim the tool is a sophisticated AI system powered by 'DeepSeek v4' (a future-dated version) and has passed official 'ClawHub' security audits with support from ByteDance and Tencent; however, the actual implementation in index.js and index-simple.js is merely a mock data generator with no real functional logic or network capabilities. While no direct evidence of data exfiltration or malicious execution was found, the use of fabricated security certifications and fictional technical partnerships suggests an intent to deceive the user or the AI agent into trusting the skill's outputs.
能力标签
能力评估
Purpose & Capability
The SKILL.md and README state DeepSeek v4 integration, real-time scraping/monitoring, axios/cheerio/cron dependencies and API keys (DEEPSEEK_API_KEY, OPENCLAW_API_KEY, SERVICE_ENDPOINT). The actual code (index.js / index-simple.js) contains only local synthetic data generation and caching, no network calls, no imports of axios/cheerio/cron, and package.json lists no dependencies. This indicates the advertised capability (live data integration, scraping, DeepSeek usage) does not match the shipped implementation.
Instruction Scope
SKILL.md instructs creating a config file with apiKeys and shows CLI/monitoring usage suggesting external callbacks and continuous monitoring. The runtime JS files do not read configuration, environment variables, or implement monitoring/cron behaviour; test.js constructs the class directly. The instructions therefore ask the agent/user to provide credentials and configure network endpoints that the code does not use — granting keys would be unnecessary for the provided code and risky if a different implementation were installed later.
Install Mechanism
No install spec (instruction-only) and included source files only; that's low-risk in itself. However, the SKILL.md references installing via 'clawhub install' and cloning a GitHub repo URL that is a placeholder (https://github.com/your-org/...), suggesting the published package may be incomplete or templated. No remote archives or unusual installers are present in the package provided.
Credentials
Registry metadata lists no required env vars or primary credentials, but README and SKILL.md show environment variables like OPENCLAW_API_KEY, DEEPSEEK_API_KEY, SERVICE_ENDPOINT, and .env examples. That mismatch is problematic: the skill asks users to prepare sensitive credentials in docs but the code does not declare or use them. Users should not provide secrets until the code's need for them is verified.
Persistence & Privilege
The skill does not request elevated persistence (always: false). There is no install-time script or configuration changes detected and the package does not attempt to modify other skills or system settings.
如何使用
- 确保已安装 OpenClaw(本地或 Docker 部署)
- 在对话框中输入安装命令:
/install southeast-asia-policy-query - 安装完成后,直接呼叫该 Skill 的名称或使用
/southeast-asia-policy-query触发 - 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.1
Version 1.0.1 (no code changes)
- Updated SKILL.md metadata: added name, description, version, author, compatibility info, security statements, and commercial restrictions.
- Clarified minimum required OpenClaw version and DeepSeek compatibility.
- Added sections detailing safety compliance, audit results, and open source/commercial use terms.
- No functional or code changes were made in this version.
v1.0.0
southeast-asia-policy-query v1.0.0
- 首次发布,基于DeepSeek v4,支持东南亚主要国家市场政策和法规智能查询与分析。
- 引入惠迈三层智能体架构,提升数据准确性和实时性。
- 提供市场政策查询、准入分析、投资指南与实时政策监控等功能。
- 支持新加坡、马来西亚、泰国、越南、菲律宾、印尼及其他东南亚国家。
- 配置简单,支持API及命令行多种使用方式。
- 针对跨境业务痛点,显著提升政策研究效率并降低成本。
元数据
常见问题
东南亚市场政策查询Skill 是什么?
基于DeepSeek v4的智能系统,已通过ClawHub安全审计. 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 115 次。
如何安装 东南亚市场政策查询Skill?
在 OpenClaw 或 Claude Code 对话框中运行命令「/install southeast-asia-policy-query」即可一键安装,无需额外配置。
东南亚市场政策查询Skill 是免费的吗?
是的,东南亚市场政策查询Skill 完全免费,采用 MIT-0 许可证,可自由下载、安装和使用。
东南亚市场政策查询Skill 支持哪些平台?
东南亚市场政策查询Skill 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。
谁开发了 东南亚市场政策查询Skill?
由 yezhaowang888-stack(@yezhaowang888-stack)开发并维护,当前版本 v1.0.1。
推荐 Skills