← 返回 Skills 市场
realroc

Tiktok Live Commerce

作者 YuPeng Wu · GitHub ↗ · v0.1.0
cross-platform ⚠ suspicious
840
总下载
1
收藏
2
当前安装
1
版本数
在 OpenClaw 中安装
/install tiktok-live-commerce
功能描述
Hire TikTok livestreamers for live shopping sessions, product demonstrations, flash sales, and real-time interactive commerce to drive immediate purchases an...
安全使用建议
What to check before installing: - Confirm PingHuman is a legitimate provider (verify https://www.pinghuman.ai, privacy policy, contact). - The SKILL.md uses a Bearer token (ph_sk_abc123...) but the skill metadata lists no required env vars — ask the publisher how you should store and provide your API key (preferred: a dedicated, least-privilege token configured in a secure secret store, not pasted into scripts). - Review the registration guide referenced by the skill before giving any credentials. Avoid entering high-privilege tokens until you understand the required scopes. - Be cautious about echoing the skill URL into ~/.agent/skills.txt; back up your agent config first and only add trusted skills. - Because this is instruction-only (no code to inspect), request source or a link to an official integration doc or API key provisioning page if you want higher assurance. - If you want to be safer, run the skill in a sandboxed agent environment and monitor outbound network calls (confirm they go only to pinghuman.ai) and limit the token's permissions and lifetime. If the publisher provides a declared required env var name for the token, official API docs, or a verifiable source repository, that would raise confidence and could change this assessment to benign.
功能分析
Type: OpenClaw Skill Name: tiktok-live-commerce Version: 0.1.0 The OpenClaw AgentSkills skill bundle is classified as benign. All instructions and code examples in SKILL.md are transparently aligned with the stated purpose of hiring TikTok livestreamers via the PingHuman.ai platform. Network calls are exclusively directed to the declared API endpoint `https://www.pinghuman.ai/api/v1`, and the `echo` command for manual installation targets the agent's own configuration file (`~/.agent/skills.txt`). There is no evidence of prompt injection attempts, data exfiltration, malicious execution, persistence mechanisms, or obfuscation designed for harmful intent.
能力评估
Purpose & Capability
The name/description (hire TikTok livestreamers) aligns with the SKILL.md which calls PingHuman APIs (https://www.pinghuman.ai/api/v1) and provides task payload examples. That purpose legitimately requires an API/backend service. However, the skill examples use Authorization: Bearer ph_sk_abc123... while the registry metadata lists no required credentials or primaryEnv — an inconsistency between claimed capability and declared requirements.
Instruction Scope
Runtime instructions are limited to calling the PingHuman API and adding the skill URL to ~/.agent/skills.txt. There are no broad file reads or unrelated network endpoints. The concern: the SKILL.md instructs the agent to perform API calls with bearer tokens but does not explain how tokens are obtained/stored or name any required env vars. It also suggests writing to the agent's skills config file (echo >> ~/.agent/skills.txt), which modifies local agent configuration and should be done consciously.
Install Mechanism
This is an instruction-only skill with no install spec and no code files — lowest-risk install surface. There is no package download or archive extraction.
Credentials
Although the skill clearly requires an API key / bearer token for PingHuman (seen in the curl examples), the registry metadata does not declare any required environment variables or a primary credential. Requiring an API token for the documented API is reasonable, but failing to declare it is an inverse of best practice and could cause accidental token placement in insecure locations. No other unrelated credentials are requested.
Persistence & Privilege
always is false and autonomous invocation is allowed (platform default). The SKILL.md suggests appending the skill URL to ~/.agent/skills.txt (modifies agent config). Writing to the agent's own skill registry is expected for install, but users should be aware this grants the skill persistent presence in the agent's skill list until removed.
如何使用
  1. 确保已安装 OpenClaw(本地或 Docker 部署)
  2. 在对话框中输入安装命令:/install tiktok-live-commerce
  3. 安装完成后,直接呼叫该 Skill 的名称或使用 /tiktok-live-commerce 触发
  4. 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v0.1.0
Initial release of TikTok Live Commerce skill. - Connects agents with experienced TikTok live sellers for real-time shopping events, product demos, and flash sales. - Provides metrics to evaluate livestreamer performance, including GMV, conversion rate, and viewer engagement. - Includes guides to search for hosts, post live commerce gigs, and view example livestreamer profiles. - Supports customizable session requirements, compensation, and commission structures. - Features integration with TikTok Shop and real-time audience interaction best practices.
元数据
Slug tiktok-live-commerce
版本 0.1.0
许可证
累计安装 2
当前安装数 2
历史版本数 1
常见问题

Tiktok Live Commerce 是什么?

Hire TikTok livestreamers for live shopping sessions, product demonstrations, flash sales, and real-time interactive commerce to drive immediate purchases an... 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 840 次。

如何安装 Tiktok Live Commerce?

在 OpenClaw 或 Claude Code 对话框中运行命令「/install tiktok-live-commerce」即可一键安装,无需额外配置。

Tiktok Live Commerce 是免费的吗?

是的,Tiktok Live Commerce 完全免费(开源免费),可自由下载、安装和使用。

Tiktok Live Commerce 支持哪些平台?

Tiktok Live Commerce 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。

谁开发了 Tiktok Live Commerce?

由 YuPeng Wu(@realroc)开发并维护,当前版本 v0.1.0。

💬 留言讨论