Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
Codesee
v1.0.0CodeSee integration. Manage data, records, and automate workflows. Use when the user wants to interact with CodeSee data.
⭐ 0· 49·0 current·0 all-time
byVlad Ursul@gora050
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Benign
high confidencePurpose & Capability
The skill describes a CodeSee integration implemented via the Membrane CLI. Recommending the Membrane CLI and a Membrane account is coherent with the stated goal of interacting with CodeSee data.
Instruction Scope
SKILL.md directs the agent/user to install and use the Membrane CLI, perform OAuth-style browser login, list connections/actions, run actions, and proxy requests to the CodeSee API. It does not instruct reading unrelated system files, environment variables, or exfiltrating data to unexpected endpoints.
Install Mechanism
There is no formal install spec in the registry metadata (instruction-only skill), but SKILL.md instructs installing the @membranehq/cli npm package globally (npm install -g) or using npx. Installing an npm package is expected for this integration, but global installs require write access to the system and you may prefer npx or a controlled environment.
Credentials
The skill declares no required environment variables or credentials and explicitly instructs not to ask users for API keys, relying on Membrane to manage auth. The requested access (a Membrane account and network connectivity) is proportionate.
Persistence & Privilege
The skill does not request always: true or other elevated persistent privileges and does not instruct modifying other skills or system-wide agent settings.
Assessment
This skill is internally consistent: it uses the Membrane CLI to talk to CodeSee and does not ask for unrelated secrets. Before installing, verify you trust the @membranehq/cli npm package and the Membrane service (review their homepage/privacy), and prefer using npx or installing the CLI in a contained environment if you want to avoid a global npm install. Be aware that using the skill grants Membrane access to whatever CodeSee data you connect to, so only connect accounts/projects you are comfortable sharing with that service.Like a lobster shell, security has layers — review code before you run it.
latestvk972nnywk8cvspf9x70t0rq8kh845e4f
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
