cao-dewang

v0.1.0

Information assistant for Cao Dewang 曹德旺. Get biography, latest news, career highlights, and social media updates.

0· 34·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Benign
high confidence
Purpose & Capability
Name, description, and requested resources align: the skill is an information assistant about Cao Dewang and does not request unrelated binaries, credentials, or config paths.
Instruction Scope
SKILL.md is concise and limited to using web search for biography, news, and social media. This is appropriate for the purpose, but the instructions are vague about which search engines, APIs, or social-media endpoints to use and provide no guidance on source selection, rate limits, or content-handling. That vagueness gives the agent broad discretion at runtime (expected for an instruction-only skill) — not a direct security mismatch, but worth noting.
Install Mechanism
No install spec and no code files. Instruction-only skills are low-risk because they don't write code or binaries to disk.
Credentials
The skill declares no required environment variables, credentials, or config paths. This is proportionate to an information lookup assistant.
Persistence & Privilege
always is false and the skill does not request persistent or elevated privileges. The default ability to be invoked autonomously by the agent is normal and not by itself a concern.
Assessment
This skill appears coherent and low-risk: it only describes using web search to gather public information and asks for no secrets or installs. Before installing, consider: (1) source provenance — the author/homepage is missing, which reduces trust; (2) the instructions are intentionally vague about which search engines or social APIs will be used, so review agent runtime logs or restrict which connectors the agent can use if you need control over external calls; (3) if you want stricter behavior, ask the author for an expanded SKILL.md that lists allowed sources and how social-media scraping is performed. If you are concerned about agents making arbitrary outbound requests, keep autonomous invocation disabled for agents using this skill or monitor outbound activity.

Like a lobster shell, security has layers — review code before you run it.

latestvk9715q007adb6772kxhy6mvbss840q3z

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Runtime requirements

Clawdis

Comments