瀑布流特定画风采图员 (The Vibe Harvester)
MaliciousAudited by ClawScan on May 10, 2026.
Overview
This skill explicitly tells the agent to harvest images while evading website anti-bot protections, including randomized human-like scrolling and slider CAPTCHA handling.
Do not install this skill in its current form. It should be rewritten to avoid anti-bot/CAPTCHA bypass, respect site restrictions, add clear download and time limits, and ask the user before taking any high-impact browser actions.
Findings (1)
Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.
The agent could use the user's browser to bypass site protections and automatically download content, potentially causing account, platform, or legal consequences for the user.
The skill directs the agent to make automated browsing harder to detect and to handle CAPTCHA-style anti-bot prompts instead of stopping.
“避免机械式的匀速翻页被网站识别为爬虫,应加入随机停顿时间” … “滑动验证码” … “模拟鼠标进行点击关闭或滑动操作”
Remove anti-bot and CAPTCHA-bypass instructions, require explicit user approval and stopping limits, and use official APIs or site-supported download methods.
