Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

GT7 Tuner — Gran Turismo 7 AI Tuning Assistant

v1.0.0

AI tuning assistant for Gran Turismo 7. Send a photo of your GT7 settings screen → get a complete optimized tune via GT Pro Tune calculator. Supports all 581...

0· 67·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Suspicious
View report →
OpenClawOpenClaw
Benign
high confidence
Purpose & Capability
Name/description (GT7 tuning assistant) match the instructions: the SKILL.md describes reading a screenshot, extracting values with vision/OCR, and automating GT Pro Tune's web app to retrieve a tune. Required resources (none) are proportionate to that purpose.
Instruction Scope
Instructions focus on OCR, unit conversion, user confirmation, and browser automation of https://app.gtprotune.com. They include in-page JavaScript eval snippets to select typeahead items and click buttons — this is necessary for web automation but does execute arbitrary JS in the page context. The doc advises not to log credentials but does not define how or where credentials should be stored by the agent.
Install Mechanism
Instruction-only skill with no install steps or third-party downloads. No code files to write or arbitrary network installs are requested.
Credentials
No environment variables, keys, or unrelated credentials are requested. The only external account referenced is the GT Pro Tune account (appropriate for the described integration).
Persistence & Privilege
Skill is not forcing permanent inclusion (always: false) and does not request system-wide configuration changes or access to other skills' credentials. The skill can be invoked by the agent (default), which is expected for this kind of automation.
Assessment
This skill appears to do what it says: read GT7 screenshots and drive the GT Pro Tune web app to produce setups. Before using it: (1) Do not paste your GT Pro Tune password into chat — prefer entering credentials only when the agent's browser automation prompts a secure login flow. (2) Consider testing with a throwaway/free GT Pro Tune account if you are uneasy about automation interaction. (3) Be aware the skill runs JavaScript in the GT Pro Tune page (eval/click); that's normal for web automation but means the agent will execute code in the page context. (4) If you require guarantees about credential storage or retention, ask the skill author how credentials are handled (the SKILL.md advises not to log them but gives no storage details). Otherwise this skill is internally consistent with its purpose.

Like a lobster shell, security has layers — review code before you run it.

latestvk971b8zbe10yvts59d1gxp79n9839h2e

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Runtime requirements

🏎️ Clawdis

Comments