taobao-shop-catalog — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited taobao-shop-catalog (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
shopId → paginated shop product listing (itemId, title, image URL)
All process output to user (progress updates, process notifications) follows the user's language.
Navigate to a Taobao or Tmall shop's catalog page and extract product listings.
https://shop{shopId}.taobao.com/category.htmIf browser-act has been confirmed available in the current session → skip this step.
Invoke browser-act via Skill tool to load usage. If installation or configuration issues arise, follow its guidance to resolve then retry.
If login status for Taobao has been confirmed in the current session → skip this step.
Otherwise: open https://www.taobao.com and observe the page header:
User refuses or cannot log in → terminate execution.
This Skill's operational boundary = what the user can manually do in their browser. It only reads data already displayed to the user on the page, never bypassing authentication or access controls. JS code is encapsulated in Python files under thescripts/directory, invoked viaeval "$(python scripts/xxx.py {params})".$(...)is bash syntax; it is recommended to use the bash tool for execution.
Navigate to the shop's catalog page, then extract:
navigate "https://shop{shopId}.taobao.com/category.htm?search=y&pageNo={page}"https://{shopName}.tmall.com/category.htm?search=y&pageNo={page}search=y parameter activates the paginated search modewait stableeval "$(python scripts/extract-catalog.py '{shopId}' --page {page})"Parameters:
shopId: numerical shop ID (e.g., 67095450); found in shop URL as shop{shopId}.taobao.com--page: page number, 1-based, default 1Output example:
[
{
"itemId": "1041516493508",
"title": "绿联T8梯形排插插座转换器插线板大间距宿舍桌面充电多孔位插排",
"imageUrl": "https://img.alicdn.com/imgextra/...",
"itemUrl": "https://detail.tmall.com/item.htm?id=1041516493508"
}
]Notes:
price is not included — Taobao shop catalog pages use font-based price obfuscation that cannot be decoded via DOM extraction. Use the taobao-product-detail skill to fetch prices for specific items.imageUrl may be a lazy-loaded URL from data-ks-lazyload-custom attribute when the image has not scrolled into viewError handling: if result count = 0, check that the page loaded correctly (screenshot), confirm the shopId is valid, and retry. Some shops may be Tmall-only and require following the redirect URL.
URL Pagination: URL pattern https://shop{shopId}.taobao.com/category.htm?search=y&pageNo={N} (or https://{shopName}.tmall.com/category.htm?search=y&pageNo={N} after redirect), increment pageNo from 1. Each page returns up to 60 items. Termination: when result count = 0 or next page link href with pageNo={N+1} is absent from the DOM.
Next page link selector: a[href*="pageNo"] (contains the next page number).
result count >= 1 and itemId non-null rate = 100%
taobao-product-detailcategory.htm view; category-specific browsing requires clicking category links in the shop navshop{id}.taobao.com to {name}.tmall.com changes the URL structure; the script handles bothPath: {working-directory}/browser-act-skill-forge-memories/taobao-shop-catalog.memory.md
Before execution: If the file exists, read it first — it records unexpected situations encountered during past executions (e.g., a strategy has become ineffective); adjust strategy order accordingly.
After execution: If an unexpected situation is encountered (strategy became ineffective, page redesigned, anti-scraping upgraded, better path discovered), append a line: {YYYY-MM-DD}: {what happened} → {conclusion}
Normal execution does not write to the file. Do not record what keywords were used or how many results were returned — those are task outputs, not experience.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.