Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
Starloop
v1.0.0Starloop integration. Manage data, records, and automate workflows. Use when the user wants to interact with Starloop data.
⭐ 0· 27·0 current·0 all-time
byVlad Ursul@gora050
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Benign
high confidencePurpose & Capability
The name/description (Starloop integration) align with the instructions (use the Membrane CLI to discover connectors, create connections, run actions, and proxy API requests). Nothing in SKILL.md requests unrelated capabilities or credentials.
Instruction Scope
Instructions are limited to installing/using the @membranehq/cli, performing browser-based login, listing/creating Membrane connections, running actions, and proxying API calls. This is within scope, but proxying and action execution will send data through Membrane's service — users should understand data will flow to Membrane and possibly to Starloop via Membrane.
Install Mechanism
There is no formal install spec (skill is instruction-only). The README instructs installing an npm global package (npm install -g @membranehq/cli). Installing a third-party global npm package is a standard but non-trivial action — trust in the @membranehq package is required.
Credentials
The skill declares no required environment variables or credentials and the instructions explicitly avoid asking for local API keys (they rely on Membrane-managed connections). This is proportionate to the stated purpose. Be aware that using Membrane grants that service access to the connected Starloop account.
Persistence & Privilege
The skill is not always-enabled and does not request persistent system privileges. It's instruction-only and does not modify other skills or system-wide settings.
Assessment
This skill is internally consistent: it tells the agent to use the Membrane CLI/service to manage Starloop data rather than asking for Starloop API keys. Before installing or running it, verify you trust Membrane (@membranehq on npm and getmembrane.com) because the CLI and Membrane service will handle your credentials and proxy requests (i.e., data will flow through their servers). If you must avoid third-party services or global npm installs, do not use this skill. Otherwise, review Membrane's privacy/permissions and the npm package source (GitHub repo/release) before proceeding.Like a lobster shell, security has layers — review code before you run it.
latestvk970fwt08a95p82b9f014ryb65849k63
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
