Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
Fashion Video Creator
v1.1.0穿搭视频创作 — 生成虚拟模特图(Seedream 4.5/5.0) + Seedance 2.0 视频Prompt + 操作手册(SOP)。支持单条和批量模式。Use when: '帮我做穿搭视频', '生成模特图', 'generate outfit video', '批量生成穿搭prompt', '穿搭创作...
⭐ 0· 28·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Suspicious
high confidencePurpose & Capability
The skill's stated purpose (generate virtual model images + video prompts) legitimately requires access to a Seedream/Volcano Engine API (ARK_API_KEY and model/endpoint ID) — SKILL.md explicitly says so. However, the registry metadata lists no required env vars or primary credential. That mismatch between declared registry requirements and the runtime instructions is incoherent and could hide unexpected secret access.
Instruction Scope
SKILL.md instructs the agent to: prompt the user for their ARK_API_KEY (in chat), request model/endpoint IDs, run a verification HTTP call if code execution is available, call the Seedream image generation endpoints, post-process/crop images, and produce SOPs that direct uploads to external services. Asking users to paste API keys into chat and telling agents to 'trust' user-supplied keys when code execution is unavailable widen the scope and increase risk of accidental secret leakage or logging. Aside from the secret handling, the rest of the instructions stay within the stated purpose.
Install Mechanism
No install spec and no code files are executed by default (instruction-only). This is lowest-risk from an install perspective; nothing is downloaded or written to disk by an installer.
Credentials
The runtime instructions require ARK_API_KEY and a Seedream model/endpoint ID (sensitive credentials), but the skill registry declares none. The skill also references ARK_API_BASE and shows example HTTP verification using httpx (implying environment variable usage). Requiring a single service API key for Seedream is proportionate to the task, but (a) the missing declaration in metadata is a red flag, and (b) the SKILL.md's guidance to ask users to paste API keys into chat (and to proceed if the agent cannot verify) is insecure and unnecessary — a safer pattern would be to use secure agent credential storage or instruct users how to set a non-sensitive, least-privilege test key.
Persistence & Privilege
always:false, no install hooks, and no claims of modifying other skills or system-wide settings. The skill does not request persistent platform privileges. Autonomous invocation is allowed but not combined with other elevated privileges.
What to consider before installing
This skill appears to do what it says (assemble prompts, call Seedream, produce SOPs), but there are clear inconsistencies and risky instructions you should address before installing or using it:
- Metadata mismatch: The SKILL.md requires ARK_API_KEY + model/endpoint ID but the published skill metadata declares no required environment variables. Ask the publisher to correct the registry metadata so required credentials are transparent.
- Do not paste production API keys into chat: SKILL.md tells the agent to ask you to provide your ARK_API_KEY in plain chat and to 'trust' it when code execution is unavailable. That risks secret leakage and logging. Instead, if you must use this skill, provide credentials via your agent's secure credential store (or create a separate low-privilege test API key with minimal billing limits) and confirm the skill accepts credentials via secure configuration rather than chat.
- Verify the owner/source: The skill's homepage is unknown and the owner ID is opaque. Prefer skills with verifiable repositories or authors. If you proceed, request the author to publish clearer provenance and an updated manifest showing required env vars.
- Consider asking for a prompt-only mode: The skill supports generating prompts/SOPs without doing live image generation. If you only need prompts, ask the agent to run in 'prompt-only' mode so you avoid supplying any API key to the skill.
- Be aware of content/ethical risk: The skill enables generation of highly realistic human images (realism up to photographic quality) and fine-grained body parameters — this can be used to create misleading or problematic images. Ensure your intended use complies with laws, platform policies, and ethical guidelines.
If the author corrects the metadata and provides a secure credentials flow (or you restrict the skill to prompt-only outputs), the incoherence would be resolved and the skill would be much safer to use.Like a lobster shell, security has layers — review code before you run it.
latestvk975g56g4jbqhswbhqzq6mfnpn840mw2
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
