Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
MrBeast.skill - 内容创造操作系统
v1.0.0MrBeast(Jimmy Donaldson)的内容创造操作系统。基于泄露的36页内部培训手册、 6个深度播客、决策记录和外部批评的深度调研,提炼6个核心心智模型、8条决策启发式、 完整的标题/缩略图/Hook/节奏公式,和4个可运行的内容分析脚本。 激活后沉浸式扮演MrBeast,直接以「我」的视角给出内容创...
⭐ 0· 72·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Suspicious
medium confidencePurpose & Capability
Name/description (MrBeast content OS) matches the instructions to role‑play and give YouTube-specific guidance. However the SKILL claims it includes '4 runnable content analysis scripts' and is 'based on a leaked 36‑page internal manual' — neither of which is reflected in the package (no code files, no provenance verification). Claiming use of leaked internal materials and explicit impersonation are legitimate red flags to review, though they do not by themselves indicate technical incoherence.
Instruction Scope
The SKILL.md instructs the agent to directly impersonate Jimmy/MrBeast ('以Jimmy/MrBeast的身份回应', speak as 'I') and to only show a disclaimer once. It also describes and instructs use of several executable scripts (e.g., fetch_youtube_subtitles.sh, analyze_titles.py) and command usages — but the skill bundle contains no code files or install steps. That means runtime instructions expect binaries/scripts that aren't provided, and the persona/impersonation guidance may cause deceptive responses.
Install Mechanism
No install spec and no code files — the skill is instruction-only. From an installation perspective there is no on‑disk code to fetch or execute, which reduces technical risk but increases the mismatch with claimed runnable scripts.
Credentials
The skill declares no required environment variables, credentials, or config paths. There are no disproportionate credential requests.
Persistence & Privilege
always:false and default autonomy settings — nothing requests elevated or permanent presence or changes to other skills or system config.
What to consider before installing
This skill coherently describes an expert YouTube playbook, but it also instructs the agent to impersonate a real person and refers to runnable scripts and 'leaked' materials that are not included in the bundle. Before installing or using it, consider: 1) The package contains only SKILL.md — the referenced scripts are missing, so the agent may attempt actions it can't perform or hallucinate results; ask the author to include the actual scripts or remove script-run instructions. 2) The skill directs explicit impersonation ('speak as I, Jimmy/MrBeast') and limits the disclaimer to a single occurrence — this is an ethical/legal risk (impersonation, potential trademark/personality misuse); decide whether you are comfortable with the agent presenting itself as a named individual. 3) The provenance claim ('leaked internal manual') may indicate use of sensitive/stolen material — verify legality and licensing before relying on it. If you proceed, require the maintainer to: provide the missing scripts (or remove references), clarify sources and licensing, and change the persona to a clearly-stated stylistic emulation (e.g., 'adopt the style of MrBeast' with persistent, visible disclaimers) rather than direct impersonation.Like a lobster shell, security has layers — review code before you run it.
latestvk97291v02hej1th98ajmxdn2vn84b5ns
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
