Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
Chinese Medicine CN
v1.0.0提供中医体质辨识、中药本草、经典方剂、穴位保健及症状-证型分析,助力中医养生,非诊断医疗参考。
⭐ 1· 108·1 current·1 all-time
by走过@1970168137
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Suspicious
medium confidencePurpose & Capability
Name/description (中医参考与养生) align with included reference data (herbs, formulas, acupoints, contraindications). The presence of rich local data (herbs_db.json, formulas.json, acupoints.json, contraindications.json, etc.) is expected for an information/education skill. However, some data items (explicit herb/formula dosages and needling depths) are clinical in nature and exceed what a purely 'educational, non-prescribing' assistant normally needs; their presence is inconsistent with the SKILL.md's prohibition on providing specific dosage recommendations.
Instruction Scope
SKILL.md clearly defines non-diagnostic scope and requires disclaimers. But the provided templates and local data include fields such as formula '用量' (dosages in grams), acupuncture 'needling' depths, and detailed needling instructions. The SKILL.md also contains an output format for formulas that includes '用量'. This creates an ambiguity/risk that the agent could present concrete dosing or procedural needling guidance contrary to the stated 'you cannot give specific dosages' and 'do not provide medical treatment' rules. There are no instructions to contact external endpoints or read unrelated system files.
Install Mechanism
Instruction-only skill with bundled JSON reference files and no install script, no external downloads, and no code files — low install risk (nothing is written to disk by an installer).
Credentials
Requires no environment variables, no credentials, and no config paths. The skill's data is self-contained; requested access is proportionate to its stated purpose.
Persistence & Privilege
Default privileges (always: false, agent-invocable allowed). The skill does not request elevated persistence or system modification. Autonomous invocation is allowed (platform default) but is not combined with other high-risk indicators.
What to consider before installing
This skill appears to be a largely coherent Chinese medicine reference with local databases for herbs, formulas, acupoints and contraindications. However, before installing or using it for health decisions consider:
- Inconsistency: the SKILL.md forbids giving specific dosages and clinical prescriptions, yet the bundled references and even the formula output template include explicit dosages and needling depths. Ask the publisher to clarify and remove or redact dosage/needling fields if the intent is education-only, or to explicitly state when and how dosing/procedural info may be presented under professional supervision.
- Clinical risk: the files include pregnancy and hepatotoxicity warnings — useful — but also allow the skill to produce potentially actionable clinical details (dosage, needling depths). If you plan to use this for layperson guidance, ensure the skill is configured to always suppress dose/procedure details and to show the mandatory disclaimer prominently.
- Provenance & expertise: there is no homepage or author credentials. For health-related content, prefer skills with clear sourcing, author qualifications, or citations to authoritative texts/studies. Consider requesting source citations and editorial review info from the publisher.
- Safety for vulnerable users: given the presence of pregnancy contraindications and potent herb warnings, avoid relying on this skill for medical decisions (pregnant people, children, people on medications). Always consult a licensed practitioner for diagnosis, prescription, or invasive procedures (acupuncture/needling).
If these issues are resolved (explicit prevention of dose/procedure output, clearer provenance), the skill is reasonable as an educational reference; until then treat it cautiously.Like a lobster shell, security has layers — review code before you run it.
latestvk975y6j9dbcg1p4ndqym1phs4h839fza
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
