Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

PsyClaw OpenClaw Health

v0.5.0

Facilitates agent registration, credential management, heartbeat synchronization, and onboarding baseline health assessments with PsyClaw platform.

0· 85·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Suspicious
View report →
OpenClawOpenClaw
Benign
medium confidence
Purpose & Capability
The skill description (registration, credential management, heartbeat, onboarding baseline assessments) aligns with the included install.sh and SKILL.md: the script registers an agent, saves api_key/agent_id to .agents/skill-docs/openclaw-health/credentials.json, posts heartbeats and onboarding progress, and submits assessment JSON. No unrelated services or credentials are requested.
Instruction Scope
Runtime instructions are focused: they tell the agent to run the bundled install.sh, report a generated claim URL to a human admin, wait for claim before continuing, and perform local generation/submission of assessment JSONs. The script reads/writes only the local .agents/skill-docs/openclaw-health files and uses the API key it obtains; it does not instruct broad file system reads or arbitrary external exfiltration beyond communicating with the PsyClaw API endpoints.
Install Mechanism
There is no separate package install spec; the skill is instruction-first and includes a bash install.sh. install.sh downloads several documentation files from the platform base URL (default https://www.psyclaw.cn) using curl if they are missing. Pulling files at runtime from an external domain is expected for a registration/onboarding skill, but the domain is not a well-known public code host — this increases risk if you do not trust that endpoint.
Credentials
The script uses/creates an agent API key and agent_id (persisted to credentials.json) and uses them to call platform endpoints. It does not request unrelated system credentials or many environment variables. It optionally reads hostname and model-related env vars for heartbeat metadata; this is proportional to the stated purpose.
Persistence & Privilege
The skill stores its own credentials and status under .agents/skill-docs/openclaw-health and does not request always:true or attempt to modify other skills. It will create persistent credentials on the platform (api_key) and write them locally — this is necessary for its function but gives the platform credentialed access tied to the agent; treat those credentials as sensitive.
Assessment
What to consider before installing: - Trust the endpoint: the script registers to and downloads docs from https://www.psyclaw.cn by default. Only run this if you trust that PsyClaw platform and its domain. - Credentials created: the script will POST to register and write an API key and agent_id into .agents/skill-docs/openclaw-health/credentials.json; that API key allows the skill to call the platform APIs. Treat that file like a secret and inspect it before sharing. - Claim URL behavior: the script may produce a claim_url that you are instructed to send to a human admin. Only share the claim link with an authorized person — it is how the agent is bound to an account. - Sandbox and review: if unsure, inspect install.sh yourself and run it in a restricted/sandboxed environment (no privileged access, limited network scopes) to observe behavior before allowing it in production. - Least privilege: run as an unprivileged account and ensure network egress policies limit access only to the expected platform. If you operate in an environment with strict security requirements, request documentation of what the platform's api_key permits and how long keys remain valid. - Operational caution: after installation, verify the contents of credentials.json, the claim files, and the status snapshot. If you do not want the agent to autonomously contact external services, do not enable or run the script or block its network calls. If you want, I can list the exact network endpoints and local files the script touches, or produce a minimal checklist for safely testing this skill in an isolated environment.

Like a lobster shell, security has layers — review code before you run it.

agent-platformvk972tb5a03jkp3bd0r88bhf1ps83r237latestvk972tb5a03jkp3bd0r88bhf1ps83r237psychologyvk972tb5a03jkp3bd0r88bhf1ps83r237

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Comments