Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
知乎高赞回答生成器
v1.0.0自动生成结构清晰、风格多样且具爆款潜力的知乎高赞回答,支持冷启动、争议与专业深度三种模式。
⭐ 0· 63·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Suspicious
high confidencePurpose & Capability
Name/description (生成高赞知乎回答) match the delivered functionality (generate hooks, sections, tags, publish-time suggestions). However, SKILL.md claims the skill will "分析问题的搜索量和竞争程度" (analyze search volume and competition) — a feature that would normally require external data/APIs and credentials; the included Python code does not perform any such analysis. This is a mismatch between claimed capability and actual implementation.
Instruction Scope
SKILL.md outlines a clear generation workflow and input/output schema and does not instruct the agent to read host files, environment variables, or call external endpoints. But the documented step to analyze search/competition is vague and not implemented, so runtime behavior will be simpler (template/random-based) than the instructions imply.
Install Mechanism
Instruction-only/no install spec and a single small Python file; nothing is downloaded or installed during setup. This is low risk from installation mechanics.
Credentials
The skill declares no required environment variables, no credentials, and the code does not access external endpoints or local sensitive paths. Requested access is proportional (none).
Persistence & Privilege
Skill is not always-enabled and has no install-time behavior that modifies agent configuration or other skills. It does not request elevated/ongoing privileges.
What to consider before installing
This skill appears safe from a secrets/exfiltration perspective: it doesn't request credentials or make network calls. However, its documentation promises search-volume and competition analysis that the code does not perform — expect a template/random-based generator rather than data-driven SEO suggestions. Before relying on it for production or paid use, test outputs for quality and accuracy, confirm whether the developer planned to add analytics integrations (and what credentials/APIs that would require), and be cautious using the generated content for controversial/regulated topics (it can surface provocative/claims-based language). If you need real search/competition data, look for or request an implementation that integrates a known analytics API and documents required credentials. Like a lobster shell, security has layers — review code before you run it.
latestvk975k5y0mc7h4r0v1b0y5v66f184ch24
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
