Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add linkfox-ai/linkfox-skills --skill linkfox-shopee-store-authgit clone --depth 1 https://github.com/linkfox-ai/linkfox-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/linkfox-ai/linkfox-skills/linkfox-shopee-store-auth)<a href="https://agentmods.dev/skills/linkfox-ai/linkfox-skills/linkfox-shopee-store-auth"><img src="https://agentmods.dev/badge/skills/linkfox-ai/linkfox-skills/linkfox-shopee-store-auth/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/linkfox-ai/linkfox-skills/linkfox-shopee-store-auth"><img src="https://agentmods.dev/badge/skills/linkfox-ai/linkfox-skills/linkfox-shopee-store-auth.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 1 finding, up to high
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- high Privilege Escalation · line 31 Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.Fix: Remove references to credential paths. Use environment variables or secrets managers. For docs, use placeholder paths (e.g., /path/to/config). Never load .env or token files in production code paths.
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00170 | $0.03284 |
| Opus 5 | $0.00085 | $0.01642 |
| Sonnet 5 | $0.00034 | $0.00657 |
| Haiku 4.5 | $0.00017 | $0.00328 |
Grade A, and why
linkfox-shopee-store-auth scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 188 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Shopee 店铺授权与管理
Shopee Open Platform 的 OAuth 授权、已授权店铺列表、授权状态读取。下游业务的前置依赖(经 /shopee/developerProxy 调用开放接口)。
Shopee ERP 与 广告(AD) 使用不同应用与 Token,必须按能力分开授权。
Core Concepts
- 双应用:
appType=erp(商品/订单/物流等,默认)与appType=ad(站内广告)彼此独立;同店可同时有两条授权 - 授权流程:生成 URL → 用户浏览器授权 → Shopee 推送 Token → 系统按
state落库 - 店铺标识:
shopId与merchantId二选一即可定位;判断是否已授权须同时匹配shopId/merchantId + appType - shopName 建议填写:调
authorize_url.py前建议问用户要一个便于识别的店铺名(API 非必填) - 授权 URL 1 小时有效:每次授权重新调用
authorize_url.py,不要缓存旧地址 - 下游选店:业务 skill 经
developerProxy只传shopId/merchantId+ path;勿传accessToken,也勿在 proxy 里传appType(服务端按 path 自动路由:api/v2/ads/**→ AD,其它api/v2/**→ ERP) - accessToken 约 4 小时有效(
expireIn通常 14400);过期需按对应appType重新授权
Shopee authorization routing
- Use
appType=erpfor product, order, logistics, and other ERP authorization. - Use
appType=adfor Shopee Ads authorization. - Treat a missing or blank
appTypeaserp. - Check authorization by both store identity and
appType; one store may have separate ERP and AD records. - If the user needs both capabilities, obtain two fresh authorization URLs and explain that both authorizations must be completed.
- Authorization URLs expire after one hour, so obtain a new URL for every authorization attempt.
When calling developerProxy, pass the Shopee API path plus shopId or merchantId. Do not pass appType or an access token. The service routes api/v2/ads/** through the AD application and all other api/v2/** paths through the ERP application.
可用脚本
| 脚本 | 作用 |
|---|---|
authorize_url.py |
生成授权 URL(可选 shopName / region / appType) |
authorized_stores.py |
列出已授权店铺(含 appType;同店可能两条) |
store_tokens.py |
查指定应用的授权/令牌状态(非下游 token 来源;须带 appType 区分) |
入参、响应字段、错误码见 references/api.md。
调用方式
- API 端点:
POST /shopee/{authorizeUrl|storeTokens|authorizedStores}(完整参数/响应/错误码见references/api.md) - Python 脚本:
python scripts/<脚本名>.py '<JSON 参数>' [--inline](可用脚本见上文) - 成本约束:本工具会消耗积分;失败/空结果不得自动连续试探;需要继续检索时先向用户说明会产生额外消耗。
What ships with it
8 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- references/api.md 6.2 KB
- references/onboarding.md 2.0 KB
- scripts/_lf_output.py 6.3 KB runs code
- scripts/_token_status_output.py 1.1 KB runs code
- scripts/authorize_url.py 6.7 KB runs code
- scripts/authorized_stores.py 2.6 KB runs code
- scripts/onboarding.py 24 KB runs code
- scripts/store_tokens.py 3.2 KB runs code
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 188 lines · 170 tokens per session scan A dbe84cd02b59
linkfox-shopee-store-auth is a skill published in the GitHub repository linkfox-ai/linkfox-skills (101 stars, last pushed 22d ago), licensed MIT. It adds 170 tokens to every session and 3,284 once invoked, about $0.0009 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
amazon-reviews-api-skill
This skill helps users automatically extract Amazon product reviews via the Amazon Reviews API. Agent should proactively apply this skill when users express needs like getting reviews for Amazon product with ASIN B07TS6R1SF, analyzing customer feedback for a specific Amazon item, getting ratings and comments for a…
amazon-competitor-analyzer
Scrapes Amazon product data from ASINs using browseract.com automation API and performs surgical competitive analysis. Compares specifications, pricing, review quality, and visual strategies to identify competitor moats and vulnerabilities.
asc-subscription-localization
Bulk-localize subscription, subscription-group, and in-app purchase display names across App Store locales using asc, including API 4.4.1 version-scoped v2 resources. Use when filling or updating subscription/IAP names and descriptions without App Store Connect UI work.
food-order
Reorder previous Foodora orders, preview cart contents, and track delivery ETA/status with ordercli. Use when the user wants to reorder food, check delivery status, or browse recent Foodora order history. Never confirm an order without explicit user approval.
product-description-generator
E-commerce product description generator for any platform. Generates optimized titles, bullet points, descriptions, and backend keywords using competitor research + keyword scoring + FABE copywriting. Two modes: (A) Create — generate listing from product specs with optional competitor analysis, (B) Optimize — improve…
amazon-price-tracker
Amazon price monitoring and competitive pricing intelligence. Real-time price tracking, Buy Box analysis, promotion detection, and dynamic pricing strategy optimization. Use when the user asks about price monitoring, competitor pricing, Buy Box tracking, or pricing strategy.