Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Moot Court AI

v1.0.0

Simulate a full Chinese civil court hearing with 4 role-based agents (clerk, plaintiff, defendant, judge) orchestrated by deterministic Lobster workflow.

0· 107·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
!
Purpose & Capability
Name/description describe a Lobster-orchestrated 4-agent simulation and require openclaw + lobster binaries and two model API keys, which is coherent; however the SKILL.md references running a 'moot-court.lobster' workflow and deterministic Lobster orchestration while no workflow file or runtime artifacts are included in the skill bundle. That omission makes the skill incomplete and undermines the claim it will provide the orchestration.
Instruction Scope
Instructions expect the user to prepare case files and 'initialize materials into agent workspaces', then run the lobster workflow. This reasonably implies the agent will read user-supplied files (case briefs, complaints, evidence). The instructions are otherwise high-level and do not ask for unrelated system data, but they are vague about where the lobster file comes from and how agent workspaces are populated.
Install Mechanism
There is no install script (instruction-only), so nothing is written to disk by the skill itself. This is low-risk from an install perspective, but it increases reliance on external files and binaries being present and correct.
Credentials
The two required env vars (DEEPSEEK_API_KEY, DASHSCOPE_API_KEY) match the declared model stack (DeepSeek and a DashScope-compatible Qwen endpoint). Requesting two model keys is proportionate to a multi-model orchestration; no unrelated credentials are requested.
Persistence & Privilege
The skill does not request always: true and declares no config paths. Autonomous invocation is allowed (default) but not combined with elevated persistence or cross-skill config changes.
What to consider before installing
This skill is plausible but incomplete. Before installing or providing API keys: (1) confirm the referenced 'moot-court.lobster' workflow exists and inspect it (the skill bundle does not include it); (2) verify the GitHub homepage and author to ensure the workflow is legitimate; (3) understand what local files the agents will read — do not place secrets in case files; (4) limit the API keys’ permissions or use dedicated/test keys for DeepSeek/DashScope; (5) run the skill in an isolated environment if you must test it. If the maintainer can supply the missing lobster workflow and a clear runbook, re-evaluate; otherwise treat this package as incomplete and proceed cautiously.

Like a lobster shell, security has layers — review code before you run it.

latestvk97d1xck88vax927zrgn3sdtr18378yv

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Runtime requirements

⚖️ Clawdis
Binsopenclaw, lobster
EnvDEEPSEEK_API_KEY, DASHSCOPE_API_KEY
Primary envDEEPSEEK_API_KEY

Comments