Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Interview

v3.0.0

Interview preparation system with company research, story building, and mock interview practice. Use when user mentions job interviews, interview prep, behav...

0· 353·2 current·2 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
The name/description (interview prep, company research, story building, mock interviews, salary prep, follow-ups) aligns with the included scripts that build stories and scaffold company research. However the SKILL.md references many additional scripts (mock_interview.py, prep_salary.py, draft_followup.py, analyze_role.py, identify_gaps.py, log_feedback.py) and multiple references/*.md files that are not present in the bundle. That means the skill claims capabilities it does not actually provide.
Instruction Scope
Runtime instructions and scripts operate entirely locally and only write/read JSON under a designated interview memory directory. There are no network calls, no external endpoints, and no environment variables accessed. Minor inconsistency: SKILL.md states data is stored under memory/interview/, while scripts use an absolute path under ~/.openclaw/workspace/memory/interview. The instructions also reference many missing scripts and reference docs, so following the SKILL.md will lead to missing-file errors for several workflows.
Install Mechanism
No install spec is provided (instruction-only skill with a couple of small Python scripts). Nothing is downloaded or written outside the normal workspace path by an installer.
Credentials
No environment variables, credentials, or external config paths are requested. The scripts only use the user's home directory to store files; this is proportionate for a local interview prep tool.
Persistence & Privilege
The skill does not request always:true, does not modify other skills, and does not require elevated privileges. It writes its own data into a hidden workspace directory under the user's home, which is expected for a local-memory feature.
What to consider before installing
This package appears to be a small local interview-prep tool but it is incomplete: only two helper scripts (build_story.py and research_company.py) are included while SKILL.md advertises several other scripts and reference files that are missing. Before installing or using it, consider: 1) it will create and write JSON files in ~/.openclaw/workspace/memory/interview — inspect that folder and the files it creates; 2) the research script only prints a framework (it does not fetch web data), so the skill may not deliver on promised 'comprehensive research' without additional code or data; 3) request the missing scripts/references from the author or review a complete package if you need mock interviews, salary prep, or follow-up drafting; 4) test in a sandbox or isolated environment if you want to ensure no unexpected behavior. The current issues look like an incomplete or mispackaged skill rather than overtly malicious code, but the capability mismatch means you should be cautious.

Like a lobster shell, security has layers — review code before you run it.

careervk977pfgwn2v78d1cyn9vpw4m2x82n1tthiringvk973f37b9nxwx7w7p40328dnqs82gg15interviewvk977pfgwn2v78d1cyn9vpw4m2x82n1ttjob-searchvk977pfgwn2v78d1cyn9vpw4m2x82n1ttjobsvk977pfgwn2v78d1cyn9vpw4m2x82n1ttlatestvk977pfgwn2v78d1cyn9vpw4m2x82n1ttpreparationvk973f37b9nxwx7w7p40328dnqs82gg15salaryvk977pfgwn2v78d1cyn9vpw4m2x82n1tt

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Comments