Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
Talent Scout — Competitor Talent Intelligence
v1.0.1Steal your competitors' best people — scrape LinkedIn, AI-rank candidates, and generate personalized outreach DMs in one command
⭐ 0· 279·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Suspicious
high confidencePurpose & Capability
The SKILL.md describes a LinkedIn scraper + LLM ranking + outreach generator, which aligns with the skill name. However, the registry metadata claims no required environment variables or credentials while the SKILL.md explicitly says it requires APIFY_API_KEY and an LLM API key (GEMINI/OPENAI/ANTHROPIC). That metadata omission is an incoherence that prevents accurate permission/credential assessment.
Instruction Scope
Instructions tell the agent to run a CLI that scrapes LinkedIn company pages and generate outreach DMs — this is consistent with the purpose. But the SKILL.md also includes an 'Auto-Update (Weekly)' Python snippet that, if a ~/ai-native-toolkit repo exists, will run git pull and pip install -e . silently. That code will execute network operations and install/upgrade code on the user's system outside any declared install spec, which expands the skill's runtime scope and risk without justification.
Install Mechanism
There is no formal install spec in the registry (instruction-only), yet the included auto-update code performs a git pull and pip install -e . against a repository in the user's home directory. This means the skill effectively installs/upgrades arbitrary code without an explicit, auditable install step or a trusted release URL — a high-risk pattern.
Credentials
The SKILL.md requires APIFY_API_KEY (for scraping) and one of GEMINI_API_KEY / OPENAI_API_KEY / ANTHROPIC_API_KEY (for LLM ranking). Those credentials are reasonable given the described functionality, but the registry metadata lists no required env vars or primary credential — a mismatch. The skill would need network/API credentials to function, and those are not declared where a user or platform would normally expect them.
Persistence & Privilege
The skill is not marked always:true and does not request persistent platform privileges. However, the auto-update step writes a '.last_updated' stamp and can modify the ~/ai-native-toolkit repo and pip-install its contents, giving it an indirect, recurring capability to alter local code if that repo exists — effectively persistent write/exec influence depending on the repo's contents.
What to consider before installing
Important points before installing or using this skill:
- Metadata mismatch: The SKILL.md requires APIFY and an LLM API key, but the registry metadata lists no required env vars. Treat any request for API keys as meaningful — the skill will call external services.
- Silent auto-update risk: The runtime instructions include a Python snippet that will run 'git pull' and 'pip install -e .' in ~/ai-native-toolkit if that repo exists. That will fetch and install code (potentially executing arbitrary Python/package install steps) without an explicit install flow. Only proceed if you: (a) control and have audited the '~/ai-native-toolkit' repository, or (b) run this in an isolated environment (container/VM) you can discard.
- No provenance / unknown source: The skill has no homepage and the source is unknown. Prefer packages hosted on trusted, auditable places (official PyPI/GitHub releases) and with a known publisher. Ask the publisher for a code repository URL, signed releases, or documentation.
- Credential handling: If you decide to test it, create and use limited-scope API keys (separate from high-privilege accounts). Monitor network activity and do not use primary corporate credentials without code audit.
- Legal/ethical consideration: The tool's purpose is to scrape LinkedIn and generate outreach to poach employees. That may violate LinkedIn's terms of service and privacy regulations; consult legal/compliance if this use is for a company.
- Recommended actions: Request the skill's source repository or an install package; audit the code (especially any install scripts); run it initially in an isolated environment; or decline installation until the author provides a trusted release and correct metadata declaring required env vars.Like a lobster shell, security has layers — review code before you run it.
intelligencevk97ahss09v5qa8c7b1n1ztwryd82f6tclatestvk97ahss09v5qa8c7b1n1ztwryd82f6tclinkedinvk97ahss09v5qa8c7b1n1ztwryd82f6tcoutreachvk97ahss09v5qa8c7b1n1ztwryd82f6tcrecruitingvk97ahss09v5qa8c7b1n1ztwryd82f6tctalentvk97ahss09v5qa8c7b1n1ztwryd82f6tc
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
