Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
Employee Handbook Generator (UK)
v1.0.0Generates complete, legally compliant UK employee handbooks and workplace policies tailored to business type and size. Use when someone needs an employee han...
⭐ 0· 59·0 current·0 all-time
byExternalOS@jamespatrickthom2003-star
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
Capability signals
These labels describe what authority the skill may exercise. They are separate from suspicious or malicious moderation verdicts.
OpenClaw
Suspicious
medium confidencePurpose & Capability
The name and description match the instructions: generate UK employee handbooks tailored to industry and size. However, the skill repeatedly promises 'legally compliant' output and cites specific (and recently amended) legislation (e.g., 'ERA 2025', Employment Relations (Flexible Working) Act 2023) while being instruction-only and having no declared means to fetch or verify current legal text or updates. That gap (claiming current legal accuracy without external sources) is a capability mismatch worth noting.
Instruction Scope
SKILL.md is tightly scoped: it asks for up to four inputs, then produces a structured markdown handbook and instructs the agent to cite relevant legislation and include implementable procedures. It does not instruct reading user files, env vars, or contacting external endpoints. The risk is content integrity: asking the model to cite current legislation and specific sections without providing authoritative sources can lead to hallucinated or outdated statutory references and misleading procedural wording.
Install Mechanism
There is no install spec and no code files that would be written to disk — the skill is instruction-only. That minimizes runtime file/installation risk.
Credentials
The skill requests no environment variables, no binaries, and no config paths. Requested privileges and secrets are proportional (none required).
Persistence & Privilege
always is false and there is no mechanism to modify other skills or system-wide configuration. The skill can be invoked by the agent (default autonomous invocation) but that is normal and not combined with broad privileges or credentials.
What to consider before installing
This skill is low operational risk (no installs, no credentials), but treat its legal claims cautiously. It promises handbooks 'referencing current legislation' even though it has no declared way to fetch or verify laws — the model may hallucinate statute numbers, amendment details, or produce outdated guidance. Before relying on any generated handbook: 1) Always have an employment solicitor review the final document (the SKILL.md includes this disclaimer). 2) Provide accurate, detailed company facts to reduce guessing. 3) Ask the skill to include citations with links to primary sources (and then verify those links independently). 4) Do not use the output as a substitute for professional legal advice or as a final compliance posture. If you need legally guaranteed accuracy, use a tool that sources official legislation or engage a qualified solicitor/HR provider.Like a lobster shell, security has layers — review code before you run it.
compliancevk976dgrqts0yhf92hqvsbyvwnd84fp7demployervk976dgrqts0yhf92hqvsbyvwnd84fp7dera2025vk976dgrqts0yhf92hqvsbyvwnd84fp7dhandbookvk976dgrqts0yhf92hqvsbyvwnd84fp7dhrvk976dgrqts0yhf92hqvsbyvwnd84fp7dlatestvk976dgrqts0yhf92hqvsbyvwnd84fp7dukvk976dgrqts0yhf92hqvsbyvwnd84fp7d
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
