Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
SiliconFlow 多模态服务,支持图片生成(FLUX/Qwen)、视频生成(Wan)、TTS语音合成、ASR语音识别。使用代金券支付。
v1.0.0SiliconFlow 多模态服务,支持图片生成(FLUX/Qwen)、视频生成(Wan)、TTS语音合成、ASR语音识别。使用代金券支付。
⭐ 2· 468·4 current·4 all-time
bySheldon.li@axdlee
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Benign
high confidencePurpose & Capability
Name/description (multimodal media) match the included scripts (image, video, TTS, ASR). The single required env var (SILICONFLOW_API_KEY) is the API credential you would expect for a hosted media API. No unrelated binaries, config paths, or extra credentials are requested.
Instruction Scope
SKILL.md instructs running the provided scripts and those scripts only: (1) read user-supplied files (audio/image) when appropriate, (2) POST to https://api.siliconflow.cn endpoints, and (3) download returned media URLs. There are no instructions to read unrelated files, scan system state, or send data to third parties beyond the siliconflow endpoints. Users should note that any files you pass (audio/images) are uploaded to the SiliconFlow service.
Install Mechanism
No install spec (instruction-only) is present; inclusion is low-risk. The repository contains runnable scripts but no automated downloads or external installers. The scripts list dependencies (requests, pillow) in comments — these are normal but may need to be installed in your runtime environment.
Credentials
Only SILICONFLOW_API_KEY is required and is used consistently as a Bearer token when calling the siliconflow API. No other secrets or unrelated environment variables are requested or accessed by the scripts.
Persistence & Privilege
The skill does not request permanent/always-on privileges (always: false). It does not modify other skills or system-wide configs. Autonomous invocation is allowed by default but not combined with other concerning factors here.
Assessment
This skill is internally consistent, but before installing: (1) confirm you trust the siliconflow.cn service and the API key you provide (the key gives the service access to use your voucher balance and process uploaded files); (2) be aware that any audio/images you pass will be uploaded to SiliconFlow servers; (3) ensure your runtime has the dependencies (requests, pillow) installed; and (4) if you need stricter privacy, avoid sending sensitive audio/images or use a vetted/private model provider instead.Like a lobster shell, security has layers — review code before you run it.
latestvk977marzpc69z0prr11yakcmf582461j
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
Runtime requirements
🚀 Clawdis
EnvSILICONFLOW_API_KEY
Primary envSILICONFLOW_API_KEY
