Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Uchicago

v1.0.1

提供芝加哥大学的历史、学院设置、招生、学费及奖学金信息,助力留学申请与学术了解。

0· 65·1 current·1 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
!
Purpose & Capability
The skill description (UChicago history, admissions, tuition, scholarships) implies university-specific content, but SKILL.md contains a generic 'brand profile' template about an unspecified 'important brand' and does not mention university-specific data sources or actions. This mismatch suggests the skill may not deliver what it promises.
Instruction Scope
SKILL.md is instruction-only and does not request files, environment variables, or external credentials. However the instructions are very high-level/vague (what to cover) and do not instruct the agent to use official or authoritative sources; that increases risk of incorrect or invented content.
Install Mechanism
No install spec and no code files — lowest risk from installation. Nothing is written to disk or downloaded.
Credentials
The skill requests no environment variables, credentials, or config paths — its resource needs are minimal and proportionate to an information-only skill.
Persistence & Privilege
always is false and there are no special persistence requests. The skill can be invoked normally but does not request elevated or permanent privileges.
What to consider before installing
This skill appears safe to install (no code, no credentials), but its runtime instructions don't match the advertised purpose: it's a generic 'brand' template rather than a UChicago-specific data source. If you need accurate University of Chicago information, ask the publisher to: (1) update SKILL.md to explicitly cite official sources (uchicago.edu, admissions pages, official tuition pages), (2) add explicit retrieval instructions (which websites or APIs to query), or (3) clarify that the skill synthesizes general guidance rather than authoritative facts. Until then, verify any facts produced by this skill against official university pages before relying on them.

Like a lobster shell, security has layers — review code before you run it.

latestvk9741m1zc9kvkx3kpp1kmr78h584w0ct

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Comments