SKILLEMALL.ai

BC coupon-finder

优惠券查询与领取技能。覆盖外卖券、酒店券、打车券、咖啡券、电影票、超市券等多场景,输入需求自动匹配最优活动链接。触发词: 优惠券查询, 领取优惠券, 有什么优惠, 外卖券, 外卖红包, 酒店券, 打车券, 咖啡优惠, 电影优惠, 帮我找优惠, 哪里有折扣, 推荐优惠活动, 今天有什么券, 点外卖优惠, 订酒店便宜, [品牌名]有优惠吗

ClawHub Agent Skills author: ayue-oss v1.0.5 MIT-0 4 files body ≈ 456 tokens Open the sourceclawhub.ai analyzed 3 d ago

As a process C 53/100 · Has gaps — weak spots: result and completion, when it triggers, inputs and preconditions

ProcedureInfrastructuretype and topics are labelled automatically from the skill text
JSON
Technical rating
B
87/100
safety, quality, tests
Safety 60%
95
Quality 40%
75
Run on models
none yet
Process rating
C
53/100
Has gaps
Result and completion w 14
0
Inputs and preconditions w 11
0
Failures and branches w 10
0
the three weakest of ten parameters · all ten

How to improve

  1. Say in the description WHEN to use the skill ("use when…", example requests): that is the agent's main cue.
For the model run — optional
  • Your own cases (evals/evals.json, 4–6 real requests with expected answers): the full check would then run those instead of a model-drafted suite.
  • A spec.yaml with trigger phrases and assertions — a behaviour contract for CI; `skilltest init` writes a template.

Guard findings · 5

✓ No critical or high findings

Medium and low: 5
  • low Secrets in code secret-high-entropy-token data/activities.json:67
    High-entropy token-like string (may be an id, hash or a credential) (quoted — discussed, not commanded)
    "小程序路径": "/waimai/pages/web-view/web-view?type=REDIRECT&webviewUrl=https%3A%2F%2Fof…com%2Fact%2Fcps%2Fpromotion%3Fp%3Dbc…8c2&utm_content=224a…7b8
    quoted
  • low Secrets in code secret-high-entropy-token data/activities.json:68
    High-entropy token-like string (may be an id, hash or a credential) (quoted — discussed, not commanded)
    "DeepLink": "imeituan://www.meituan.com/web?url=https%3A%2F%2Fof…com%2Fact%2Fcps%2Fpromotion%3Fp%3Dbc…8c2&utm_content=224a…a34
    quoted
  • low Secrets in code secret-high-entropy-token data/activities.json:141
    High-entropy token-like string (may be an id, hash or a credential) (detector / deny-list definition)
    "DeepLink": "tbopen://m.taobao.com/tbopen/index.html?&action=ali.open.nav&module=h5&h5Url=https%3A%2F%2Ftb.ele.me%2Fapp%2Fal…wth%2Fsgyx%2Fhome%3Ftms_force%3Dtrue%26fo…mis%3Dtrue%26_wx_s
    detector
  • low Secrets in code secret-high-entropy-token data/activities.json:176
    High-entropy token-like string (may be an id, hash or a credential) (quoted — discussed, not commanded)
    "DeepLink": "tbopen://m.taobao.com/tbopen/index.html?&action=ali.open.nav&module=h5&h5Url=https%3A%2F%2Ftb.ele.me%2Fwow%2Fz%2Funiapp%2F1100497%2Fad…app%2Fet-union%2Fhome%3Fwh_weex%3Dtrue%26weex_mo
    quoted
  • low Secrets in code secret-high-entropy-token data/activities.json:194
    High-entropy token-like string (may be an id, hash or a credential) (quoted — discussed, not commanded)
    "DeepLink": "tbopen://m.taobao.com/tbopen/index.html?&action=ali.open.nav&module=h5&h5Url=https%3A%2F%2Ftb.ele.me%2Fwow%2Fz%2Funiapp%2F1100497%2Fad…app%2Fet-union%2Fhome%3Fwh_weex%3Dtrue%26weex_mo
    quoted

Files scanned: 4. Evidence is masked. Grey chips explain why severity was lowered.

Against the Agent Skills spec

  • warning description-no-when description does not say WHEN to use the skill (no "use when")

Process rating: all ten parameters 53/100

  • 0Result and completion. Does not say what the result is
  • 0Inputs and preconditions. Does not say what the process needs to start
  • 0Failures and branches. Linear process with no failure handling
  • 0Progress reporting. Says nothing while it works
  • 20When it triggers. No condition that starts the skill
  • 100Tools and files. No external tools needed
  • 100Steps. 21 steps
  • 100Consistency. Name and required fields are in place
  • 100Execution cost. Instruction body is 456 tokens
  • 100Running it twice. No mutating operations

Everything here is measured from the skill text rather than judged by a model, so the numbers are checkable. A parameter weighs more when it is a more common reason for the process to stall.

Quality signals

  • +5Description has no quoted example phrases that should trigger the skill
  • +4Description does not say when NOT to use the skill (false activations)
  • +3Output format is not stated: the model decides each time
  • +1No license
  • +2Single-language instructions
  • +3Description length 168: enough signal without eating the budget
  • +4Structure: 10 headings
  • +3Step-by-step instructions: 21 items
  • +4Has examples (4 code blocks)
  • +3All 1 scripts are documented

Quality base 70; lint remarks subtract, signals add up to 100. Result: 75.

External checks

ClawHub: clean
This skill locally matches coupon requests to a bundled promotional-link list, with disclosed third-party links and no evidence of credential access, persistence, or hidden execution.
LLM: benign (high) · VirusTotal: · 29 May 2026