Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
Attic Ladder Installation Video
v1.0.0AI video creation for attic ladder installations, wealth management practices, independent financial planners, and registered investment advisors — generate...
⭐ 0· 48·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
Capability signals
These labels describe what authority the skill may exercise. They are separate from suspicious or malicious moderation verdicts.
OpenClaw
Suspicious
medium confidencePurpose & Capability
The skill's name (Attic Ladder Installation Video) and many keywords mention attic-ladder installation, but the SKILL.md body is almost entirely about creating marketing and educational videos for financial advisors and wealth-management topics. This mismatch suggests either a mislabeled skill, careless copy-paste, or intentional obfuscation. There is no justification in the instructions for the attic-ladder phrasing, which is inconsistent with the described capabilities.
Instruction Scope
The SKILL.md (instruction-only) appears to be a long prompt/template for producing tailored financial-advisor marketing videos (audience targeting, topics, scenarios). There are no instructions to read local files, request environment variables, or contact external endpoints. However, the instructions include targeted messaging for financially vulnerable audiences (pre-retirees, recent inheritors, widows/widowers), which raises ethical and regulatory considerations for financial advice content. The attic-ladder phrasing recurs inside the prompt (e.g., search examples), amplifying the incoherence but not adding clear technical risk.
Install Mechanism
No install spec and no code files: this is instruction-only, so nothing will be written to disk or downloaded during install. That minimizes technical risk.
Credentials
The skill declares no environment variables, credentials, or config paths. The instructions do not reference secrets or system configuration. The requested privileges are proportionate (none).
Persistence & Privilege
always is false and model invocation is not disabled (normal defaults). The skill does not request persistent system presence or modify other skills. No elevated privileges are declared.
Scan Findings in Context
[scanner.none] expected: The regex scanner found no code to analyze because this is an instruction-only skill (SKILL.md only). For instruction-only skills, absence of findings is expected but not proof of safety or coherence.
What to consider before installing
The main concern is semantic: the skill's name and keywords repeatedly mention 'attic ladder installation' but the instructions clearly target financial-advisor marketing videos. Before installing or using this skill: 1) Ask the publisher to explain the mismatch and provide a source/homepage or repository; 2) If you expected an attic-ladder how-to video tool, do not install—this skill appears to be for financial marketing instead; 3) If you plan to use it for financial content, review the full SKILL.md to ensure the tone, regulatory language, and targeting are appropriate and compliant (financial advice is regulated and ethically sensitive); 4) Because this is instruction-only and requires no credentials, the technical risk is low, but the provenance is unknown—prefer skills with an identifiable author or repo and clear purpose. If the publisher cannot clarify the mismatch, treat the skill as untrusted.Like a lobster shell, security has layers — review code before you run it.
latestvk978txxw9xsfhvbf469pmnwsth84edj2
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
