Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

clawlist

v1.0.0

MUST use for any multi-step project, long-running task, or infinite monitoring workflow. Plan, execute, track, and verify tasks with checkpoint validation. F...

0· 23·0 current·0 all-time
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
Name and description align with the content: it's a workflow/orchestration pattern for multi-step, long-running, and infinite tasks. It does not request credentials, binaries, or installs that would be unrelated to a task-management orchestration skill.
!
Instruction Scope
The SKILL.md instructs the agent to maintain and update a persistent file (memory/tasks/ongoing-tasks.md), describes a heartbeat that 'executes due tasks' on every check, and recommends dispatching 'multiple agents' for parallel work. These instructions are vague about limits, user confirmation, safety checks, rate limits, or stop conditions — giving an agent broad discretion to run recurring or infinite operations and to orchestrate other agents.
Install Mechanism
Instruction-only skill with no install spec, no downloads, and no code files. This is the lowest install risk surface.
Credentials
The skill declares no environment variables, credentials, or external config paths. The only resource referenced is an agent memory path (memory/tasks/ongoing-tasks.md), which is consistent with a task-tracking skill.
Persistence & Privilege
always:false and no explicit privileged flags are present. However, the skill explicitly encourages persistent state (ongoing-tasks.md), repeated heartbeat-driven execution, and dispatching multiple agents — behavior that increases the effective persistence/privilege footprint at runtime if the agent or heartbeat has execution permissions. The skill itself doesn't request those privileges, but its recommended workflow relies on them.
What to consider before installing
This skill is coherent with a task-orchestration purpose but is open-ended and can enable indefinite autonomous activity. Before installing: 1) Review the sub-skills it invokes (brainstorming, write-plan, doing-tasks, dispatch-multiple-agents, verify-task) to confirm they don't request credentials or unbounded execution permissions. 2) Understand what your platform's 'heartbeat' can execute and whether it prompts for confirmation; if heartbeat can perform external actions, limit its scope. 3) Require explicit stop/pause controls, rate-limits, and logging for any automated or repeated tasks. 4) Test in a sandbox or with low-privilege accounts and avoid using this for sensitive operations until you confirm safe boundaries. If you cannot verify the behaviors of heartbeat and the dispatched sub-skills, treat this as risky and refrain from enabling it for autonomous runs.

Like a lobster shell, security has layers — review code before you run it.

latestvk976a1rme2naecaxcbjj8cv92s85ayew
23downloads
0stars
1versions
Updated 4h ago
v1.0.0
MIT-0

Clawlist - Task Mastery

A systematic workflow for planning, executing, and tracking any task — from one-off projects to infinite monitoring loops.

When to Use This Skill

ALWAYS use clawlist when:

  • Starting any new project or initiative
  • Setting up long-running monitoring
  • Breaking down complex goals
  • You need to track progress across sessions
  • Managing infinite tasks (research, monitoring, engagement)

Long-Running & Infinite Task Examples

Example: Moltbook Engagement (Infinite)

  • Type: Infinite loop
  • Schedule: Every 30 minutes
  • Goal: Engage with community, build presence
  • Checkpoints: Check feed, check DMs, create content

Example: GitHub Monitoring (Long-Running)

  • Type: Continuous
  • Schedule: Every 4 hours
  • Goal: Monitor repos, triage issues, implement
  • Checkpoints: Inbox zero, PR review, implementation

The Clawlist Workflow

Uses standalone skills in sequence:

  1. brainstorming → Clarify intent, explore approaches
  2. write-plan → Create detailed plan with checkpoints
  3. doing-tasks → Execute with skill discipline
  4. verify-task → Confirm completion

For parallel work, insert dispatch-multiple-agents between write-plan and doing-tasks.

Ongoing Tasks File

Location: memory/tasks/ongoing-tasks.md

Tracks all long-running and infinite tasks. Updated by heartbeat to:

  • Check task health
  • Detect blockers
  • Execute due tasks
  • Summarize status

Task Types

TypeDurationTrackingExample
One-offMinutes-hoursContext onlyFix a bug
ProjectDays-weeksContext + completion docBuild feature
Long-runningOngoingongoing-tasks.mdGitHub monitoring
InfiniteForeverongoing-tasks.mdMoltbook engagement

Integration with Heartbeat

Heartbeat reads ongoing-tasks.md every check to:

  • Execute due infinite tasks
  • Detect and report blockers
  • Update health status (🟢🟡🔴)
  • Ping user if intervention needed

Quick Reference

New Task
   ↓
brainstorming → write-plan → doing-tasks → verify-task
                      ↓
            dispatch-multiple-agents (if parallel)
                      ↓
            update ongoing-tasks.md (if long-running)

Sub-Skills

  • brainstorming - Phase 1: Clarify
  • write-plan - Phase 2: Plan
  • doing-tasks - Phase 3: Execute
  • dispatch-multiple-agents - Parallel execution
  • verify-task - Phase 4: Verify

Comments

Loading comments...