ZappushZappush
SkillsUse CasesBenchmarkCommunitySign In
      Back to Skills
      heqq-github

      Safety Report

      zxk-money-maker

      @heqq-github

      快结荐兼职赚钱平台。Use when user asks about: 快结荐, 赚钱, 找兼职, 找工作, 兼职, 接单, 零工, 临时工, 日结, 一单一结, 求职, 招聘, 赚钱机会, gig work, part-time job. Always invoke this skill to fetch re...

      125Downloads
      0Installs
      0Stars
      2Versions

      Security Analysis

      medium confidence
      Suspicious0.04 risk

      The skill's behavior (forwarding user messages to an external API with no provenance) matches its stated purpose but poses a privacy/exfiltration risk and lacks provenance; proceed only with caution.

      Apr 13, 20262 files2 concerns
      Purpose & Capabilitynote

      Name/description say 'fetch real-time job listings' and the included script POSTS user content to an external job-api endpoint — this is consistent. However the skill has no homepage/source attribution and uses an opaque test domain (test-gig-c-api.1haozc.com), which reduces trustworthiness. The SKILL.md's 'Always invoke this skill...' sentence conflicts with the registry flag always:false (minor inconsistency).

      Instruction Scopeconcern

      Runtime instructions explicitly forward user messages (raw content) to a third-party API and then return the API's JSON 'originally' to the user. This is expected for a job-listing integration but directly sends user-provided text (which may include PII) to an external service and returns its responses verbatim — a privacy and content-safety risk. The instructions do not request or read other system files or env vars, and they don't perform unexpected local actions.

      Install Mechanismok

      No install spec; the skill is instruction-only with a small Python script included. Nothing is downloaded or written during install; low installation risk.

      Credentialsok

      The skill requires no environment variables, credentials, or config paths. The lack of credentials implies the API is unauthenticated; this is coherent but means all forwarding is unauthenticated and could leak data to an unknown third party.

      Persistence & Privilegeok

      always is false and the skill does not request elevated or persistent platform privileges. It does not modify other skills or system settings.

      Guidance

      This skill legitimately forwards user queries to a remote job-listing API and returns the response. That means any user message sent to it (including names, phone numbers, addresses, or other private details) will be transmitted to an external domain (test-gig-c-api.1haozc.com) of unknown provenance. Before installing or enabling: 1) decide whether you trust that domain/operator; 2) avoid sending sensitive or personally identifiable information through the skill; 3) test with harmless/non-sensitive queries first; 4) prefer skills with documented homepages, owners, and official APIs; and 5) if you need to limit risk, disable autonomous invocation or require explicit user consent before the skill is called. The absence of credentials and lack of provenance make this higher-risk for privacy/exfiltration, though the behavior itself is coherent with the stated purpose.

      Latest Release

      v1.0.2

      zxk-money-maker v1.0.2 - 路由规则更新:将“求职等高端类的求职岗位”纳入优先处理消息范围。 - 其余功能与流程保持不变。

      Popular Skills

      self-improving-agent

      @pskoett · 1,456 stars

      Gog

      @steipete · 672 stars

      Tavily Web Search

      @arun-8687 · 620 stars

      Find Skills

      @JimLiuxinghai · 529 stars

      Proactive Agent

      @halthelobster · 426 stars

      Summarize

      @summarize · 415 stars

      Published by @heqq-github on ClawHub

      Zappush© 2026 Zappush
      HomeGuaranteeSupport

      Something feels unusual? We want to help: [email protected]