Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

财联社自定义新闻日报

v1.0.1

自动获取财联社电报自定义关键词新闻并格式化为一句话新闻

0· 292·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Suspicious
View report →
OpenClawOpenClaw
Benign
high confidence
Purpose & Capability
Name/description indicate fetching and formatting news from 财联社电报; the instructions only require a browser tool and page interactions consistent with that purpose. No unrelated credentials, binaries, or config paths are requested.
Instruction Scope
Runtime instructions are narrowly focused on navigating the target site, finding the search box, extracting articles, and formatting output. They also instruct the agent to check for and install the agent-browser tool (via a runCommand/clawhub call) — this is within scope but worth noting because it causes the agent to invoke a system install step and network access.
Install Mechanism
The skill itself has no install spec and contains no code files. It instructs the agent to run 'clawhub install agent-browser' if the browser tool is missing; using the platform's package/install helper is expected for a browser-based skill. There are no downloads from arbitrary URLs embedded in the skill.
Credentials
The skill does not request environment variables, secrets, or other credentials. Its needs (network access and the browser tool) are proportional to scraping/searching a public news site.
Persistence & Privilege
always is false and the skill is user-invocable. The SKILL.md documents an optional cron config that, if added by the user, will schedule periodic runs — this can cause recurring autonomous execution but is opt-in and not enforced by the skill itself.
Assessment
This skill appears to do what it says: open the public 财联社 telegraph page, search for keywords, extract articles and produce one‑line news summaries. Before enabling: 1) Confirm you trust and want the agent to perform network access and to install the agent-browser tool (it runs 'clawhub install agent-browser' if missing). 2) If you don't want recurring runs, do not add the cron entry to your OpenClaw config. 3) Check the agent-browser package/source (and the skill's GitHub repo if you want more assurance) to ensure you trust what will be installed. 4) Be aware of target-site scraping and terms-of-service considerations. If you only want manual use, invoke the skill on demand and avoid adding the scheduled cron config.

Like a lobster shell, security has layers — review code before you run it.

latestvk97b95scdat51snavvt41w9axs82nwp8

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Runtime requirements

📰 Clawdis

Comments