Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Lofy Career

v1.0.0

Job search automation for the Lofy AI assistant — application tracking, resume tailoring to job descriptions, interview prep with company research, follow-up management with draft emails, and pipeline analytics. Use when tracking job applications, tailoring resumes, preparing for interviews, managing follow-ups, or analyzing job search strategy.

1· 1.5k·1 current·3 all-time
byHarreynish Gowtham@harrey401
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Suspicious
View report →
OpenClawOpenClaw
Benign
high confidence
Purpose & Capability
Name/description (job tracking, resume tailoring, interview prep, follow-ups, analytics) align with the instructions: reading a local applications JSON, reading a profile file, parsing job descriptions, performing web research, drafting emails and analytics. No unrelated credentials, binaries, or installs are requested.
Instruction Scope
Instructions explicitly tell the agent to read/write data/applications.json and read profile/career.md, perform web searches, generate tailored resume bullets and follow-up drafts, and 'send prep package 24h before'. The scope is appropriate for the stated purpose, but two items are underspecified: (1) how 'sending' or scheduling a prep package should occur (email? calendar? user prompt?) and (2) what exact locations/permissions are expected for profile/career.md and the data file. Also: web research may involve scraping social profiles or public info for interviewer research — this is expected but has privacy implications.
Install Mechanism
This is instruction-only with no install spec or code files. That minimizes disk-written code and supply-chain risk.
Credentials
The skill declares no required environment variables or credentials, which is proportionate. However, the SKILL.md references local files (data/applications.json and profile/career.md) while requires.config paths are empty — a minor inconsistency: the skill will read/write local files but does not declare them as required config paths.
scan_findings_in_context

Like a lobster shell, security has layers — review code before you run it.

latestvk9747j562qvrddek73hvn5znhh80xzjc

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Comments