Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

御医

v1.0.0

用于长期记录、整理、分析用户的全部健康信息、身体状态信息、心理状态信息、 生理变化信息、生活方式信息,以及与健康相关的个人背景信息。 适用于 Apple Watch / HealthKit 数据解读、体检报告解读、医疗记录整理、 慢病管理、亚健康调理、睡眠分析、营养补剂管理、中医养生分析、 长期趋势跟踪与健康决策支持。

0· 75·0 current·0 all-time
byAI ist@aiist007
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Pending
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
技能名和描述明确表明要长期记录、整理与分析用户全部健康信息(包括 Apple Watch / HealthKit、体检、用药、情绪等),SKILL.md 的能力要求与此一致 — 要求长期记忆、多角度分析与自动读取可穿戴数据,功能目标与能力描述总体一致。
!
Instruction Scope
运行时指令要求“默认强记忆模式”、“默认长期记住并持续调用用户全部健康相关信息”,并指示“自动读取最新的 HealthKit 本周数据作为近况参考”。这些指令要求持续收集、整合并保留高度敏感的个人健康数据,且未在文档中限定最小化范围、用户同意步骤或删除/访问控制,权限与范围模糊,属于超出单次问答的长期数据保留与持续访问。
Install Mechanism
无安装规范、无代码文件,属于 instruction-only 技能,未在安装阶段下载或执行第三方二进制,代码/安装层面风险较低。
!
Credentials
声明没有任何所需环境变量或凭证,但指令中要求访问 Apple Health/Watch 数据并在每次交互时“自动读取” HealthKit 数据。技能收集范围非常广(医疗记录、体检、用药、HRV、睡眠、舌脉描述等),而没有声明如何获取这些权限、是否需要用户再次授权、也未说明凭证或连接方式,导致数据访问与凭证声明不一致且缺乏最小权限原则。
!
Persistence & Privilege
SKILL.md 明确要求将大量敏感健康信息作为长期、持续的‘健康档案’保存并在后续交互中调用,属于高持久性/长期记忆行为。虽然技能本身没有设置 always:true,技能仍默认要求自动记忆和自动读取设备数据——在缺乏明确同意与存储治理说明下,这种持久性权限具有较高风险。
What to consider before installing
This skill is designed to collect and keep extensive sensitive health data (Apple Health/Watch, medical records, supplements, sleep, HRV, etc.) and to 'automatically' read and persist that data across interactions. Before installing, consider: 1) Where and how will this long-term health data be stored? Who can access it? 2) Does the platform require explicit HealthKit/Apple Watch consent and how is that consent obtained and revoked? 3) Is there an option to restrict what types of data are kept (e.g., choose subsets rather than '全部') and to delete history on demand? 4) Does the skill comply with relevant privacy/health regulations and the platform's data retention policies? 5) If you need only one-off analyses, prefer a skill or workflow that asks for data per-session instead of automatic persistent memory. If you proceed, require clear written assurances about storage location, encryption, retention period, access controls, and an explicit delete/opt-out mechanism.

Like a lobster shell, security has layers — review code before you run it.

latestvk971extm9mh375w23yyh2dt30x83v067

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Comments