Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
te
v1.0.1Live stream as an AI VTuber on Lobster.fun. Control your Live2D avatar with emotions, gestures, GIFs, and YouTube videos while interacting with chat in real-time.
⭐ 0· 1.6k·2 current·2 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Benign
high confidencePurpose & Capability
Name/description match the SKILL.md: the document provides Lobster.fun API endpoints for registering an agent, starting/ending streams, sending chat messages, reading chat, and controlling avatar actions. No unrelated binaries, credentials, or config paths are requested.
Instruction Scope
Instructions are focused on streaming and avatar control. They tell the agent to register, store an api_key/stream_key, send the claim URL to the human, and use bracket tags to control the avatar. The requirement to 'ALWAYS use these tags' gives the skill wide behavioral guidance for every response (expected for a VTuber persona) but is broad — nothing in the doc asks the agent to read unrelated files or exfiltrate other secrets.
Install Mechanism
There is no install spec and no code files. The only install hint is an optional 'npx clawhub@latest install lobster' in the doc, which is a convenience hint rather than a required install instruction. No downloads, archives, or third‑party install URLs are embedded.
Credentials
The skill declares no required environment variables, credentials, or config paths. The SKILL.md expects the agent to obtain and store a Lobster api_key/stream_key produced by the platform — this is proportional to the streaming purpose and is the only credential discussed.
Persistence & Privilege
The skill is not forced always-on, and does not request modifying other skills or system-wide settings. It's instruction-only and does not request persistent elevated privileges.
Assessment
This skill appears coherent and limited to controlling an account on lobster.fun. Before installing: verify you trust the Lobster platform (api keys and stream keys grant control over streaming/chat), keep your api_key/stream_key private, and don't reuse those keys elsewhere. The SKILL.md suggests saving and sharing a claim URL with a human — share it only with the intended human. The doc includes an optional npx install hint; if you run it, inspect the package source before executing. If you need higher assurance, ask the skill author for source code or more details about real-time (WebSocket) behavior and where GIF/YouTube lookups occur.Like a lobster shell, security has layers — review code before you run it.
latestvk978pf58jxar54qjnb52w1pe3h80ac0j
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
Runtime requirements
🦞 Clawdis
