Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

heursistic

v1.0.0

Master reference for 88 psychological heuristics — the complete leverage list for sales, copywriting, offer design, cold outreach, objection handling, and pe...

0· 53·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
Name/description match the actual content (a reference of persuasion heuristics). There are no requested binaries, env vars, or installs that don't belong to this purpose.
!
Instruction Scope
The SKILL.md tells the agent to 'Always trigger... without exception' whenever a task involves influencing humans, which is unusually broad and grants the skill behavioral scope beyond its registry flags. It also instructs the agent to 'Load the reference file' at /references/heuristics-full.md, but that file is not present in the package (skill is instruction-only). These are runtime/instruction inconsistencies and grant wide discretion to an invoking agent.
Install Mechanism
There is no install spec or code to download; this is instruction-only, so nothing is written to disk by an installer.
Credentials
The skill requires no environment variables, credentials, or config paths — consistent with a static reference skill.
Persistence & Privilege
Registry flags are default (always:false, agent invocation allowed). The SKILL.md's insistence that the skill be consulted 'every time, without exception' is inconsistent with the lack of always:true in metadata; this is a behavioral concern (broad invocation) but not an explicit privilege escalation in the registry.
What to consider before installing
This skill is primarily a text reference for persuasion heuristics and does not request credentials or install anything — that's good. However: (1) the runtime instructions instruct the agent to always consult this skill 'without exception,' which is unusually broad; consider whether you want the agent to be allowed to call it autonomously for all tasks that 'involve influencing humans.' (2) The SKILL.md refers to /references/heuristics-full.md, but that file isn't included — ask the publisher to provide the referenced resource or remove the instruction to 'load' it. (3) Because the content is about persuasion/manipulation, review it for ethical and legal appropriateness for your use cases. If you decide to install: restrict autonomous invocation or require user confirmation for sensitive actions, and request the missing reference file or a clearer scope statement from the author before trusting automatic, frequent invocation.

Like a lobster shell, security has layers — review code before you run it.

latestvk97dab7yg3v4aydxyf99q085e583ke75

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Comments