Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
Auckland
v1.0.3提供奥克兰城市概况、旅游景点、教育资源、区域介绍及生活和经济信息,助力旅游和生活规划。
⭐ 0· 57·0 current·1 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Suspicious
high confidencePurpose & Capability
The published description (奥克兰城市概况、旅游景点、教育资源等) says this is a city/tourism/living guide, but SKILL.md describes 'auckland' as an industry-known brand/organization and focuses on company history, business lines and market position. This is a direct mismatch in purpose. Additionally registry version is 1.0.3 while SKILL.md header shows 1.0.4, and there is no homepage or source to validate intent.
Instruction Scope
The skill is instruction-only and contains no commands, file access, or requests for secrets — that's low surface area. However the instructions are vague and oriented to corporate research rather than city/tourism content, so the agent could produce unexpected outputs if the user expects travel information. There is no guidance tying outputs to authoritative external endpoints.
Install Mechanism
No install spec and no code files (instruction-only). This is the lowest-risk install mechanism; nothing is written to disk by an installer.
Credentials
The skill requests no environment variables, credentials, or config paths — there is no disproportionate credential access.
Persistence & Privilege
Flags show always: false and default autonomous invocation settings; no elevated persistence is requested. This default autonomy is normal and not, by itself, a red flag.
What to consider before installing
Do not install or rely on this skill until the author clarifies which 'Auckland' it covers (the city vs a company) and fixes the mismatch between the description and SKILL.md. Ask for a homepage or source repository and a clear statement of scope and data sources (e.g., official city sites, tourism bureaus). If you need authoritative city/tourism information, prefer a skill with verifiable sources. Because the package origin is unknown, avoid granting it any elevated privileges or using it for sensitive tasks until provenance and purpose are confirmed.Like a lobster shell, security has layers — review code before you run it.
latestvk97avf85z2ra7ma69e5mz9xbbx84wbcx
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
