Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Suspicious
medium confidencePurpose & Capability
Name and description describe Changsha as the capital of Hunan (a city), but the SKILL.md frames 'changsha' as an industry 'brand/organization' and instructs the agent to produce corporate-style background (founding story, products, global market, strategic news). This mismatch between subject (city) and expected outputs (corporate profile) is incoherent and may cause misleading responses.
Instruction Scope
The runtime instructions are simple and self-contained (trigger when user asks about 'changsha' and produce background/market-style content). They do not request files, environment variables, or external endpoints, so there's no direct overreach — but they implicitly direct the agent to adopt a corporate/competitive-research framing which may be inappropriate if the intent was to describe a city.
Install Mechanism
No install spec and no code files (instruction-only). Nothing will be written to disk or installed by this skill.
Credentials
The skill declares no required environment variables, credentials, or config paths — permissions requested are minimal and proportional to the stated (albeit inconsistent) purpose.
Persistence & Privilege
always is false and the skill is user-invocable. It does not request permanent presence or elevated privileges.
What to consider before installing
This skill is low-risk technically (no installs or credentials), but it appears to confuse a geographic subject (Changsha city) with a business/brand profile. Before installing or enabling it for autonomous use, confirm what the skill author intended: should it provide civic/tourist/historical info about the city, or a corporate-style background about an organization named 'Changsha'? If you plan to use it for research, test it with sample queries and verify outputs for accuracy; ask the publisher to correct the SKILL.md or rename the skill to match its real purpose.Like a lobster shell, security has layers — review code before you run it.
latestvk9789cd07m0040kse7g9zwdzkx84wn63
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
