juejin-pins-publish

Security checks across static analysis, malware telemetry, and agentic risk

Overview

This skill is coherent with its stated purpose: it automates publishing user-provided posts to Juejin, using the user’s logged-in browser session.

Install only if you want OpenClaw to publish to Juejin on your behalf. Make sure the correct Chrome/Juejin account is active, review the exact text and any images or links, and consider asking for a final confirmation before the publish click.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Risk analysis

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

If invoked with the wrong content, account, image, or link, the agent could publish something publicly under the user’s Juejin identity.

Why it was flagged

The skill instructs the agent to submit a Juejin post through browser automation. This matches the stated publishing purpose, but it can create public content on the user’s account.

Skill content
点击"发布"按钮(`ref=e132`)完成发布。
Recommendation

Before allowing the final publish action, confirm the target account, post text, images, links, and selected circle/topic.

What this means

Posts will be made as the currently logged-in Juejin user, which may affect that account’s public presence.

Why it was flagged

The skill depends on the user already being logged into Juejin in Chrome, so actions are performed using the user’s existing authenticated session.

Skill content
- 用户已登录掘金账号
- Chrome 浏览器已附加 OpenClaw Browser Relay 扩展
Recommendation

Use a dedicated or clearly verified browser profile, and ensure you are logged into the intended Juejin account before invoking the skill.