潜客挖掘 - 自动搜索潜在客户,生成线索列表。支持行业、关键词搜索,导出联系方式。适用于销售、市场人员。
Security Analysis
medium confidenceThe skill claims to automatically find and export contact leads but is only a short instruction file with no code, binaries, or required credentials — the pieces don't add up.
The description promises web scraping, contact extraction, CSV/Excel export and a CLI usage example, but the package contains no code, no install, and declares no required binaries or credentials. A real 'lead generator' would normally include an implementation, dependencies, or explicit API endpoints — those are missing.
SKILL.md provides only high-level features and a single CLI usage line ('lead-generator ...') but no concrete runtime instructions for the agent (no endpoints to call, no scraping rules, no consent or data-source limits). This vagueness could cause an agent to (a) attempt to execute a non-existent CLI or (b) try arbitrary web scraping without safeguards or specified sources.
No install specification (instruction-only). That lowers direct delivery risk, but is inconsistent with the documented CLI usage — the skill references an executable that is not provided or installed, which is an incoherence rather than a safe-by-design signal.
The skill requests no environment variables or credentials but advertises an 'API access' enterprise tier — this mismatch is unexplained. Extracting contact information often requires access tokens or explicit data sources; the lack of declared credentials or config is disproportionate to the claimed capabilities.
No elevated persistence requested (always:false). The skill is not set to be force-enabled and uses default autonomous-invocation behavior; there is no evidence it modifies other skills or system settings.
Guidance
This skill is just a short README claiming a CLI and web-scraping capability but contains no implementation or install instructions. Before installing or enabling it, ask the publisher for: (1) the actual implementation (binary, source code, or API endpoints); (2) what data sources it will scrape and how consent/privacy/compliance are handled; (3) required credentials and why they're needed. Do not provide secrets or system credentials. If you need lead-generation functionality, prefer skills that include a clear install mechanism, documented endpoints, or a trusted external service integration rather than a vague instruction-only document. If you must test it, do so in a sandboxed environment and verify legal/privacy implications of scraping contact data.
Latest Release
v0.1.0
Initial release of lead-generator. - 支持按行业或关键词自动搜索和挖掘潜在客户 - 抓取并导出联系信息,生成线索列表 - 支持导出为 CSV/Excel 格式 - 提供多种套餐(免费、专业、企业)
More by @lead
Published by @lead on ClawHub