Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Prompt Generator Pack

v1.0.0

爆款 Prompt 套装。50+ 精选 Prompt 模板,涵盖写作、代码、翻译、头脑风暴、运营文案等场景。复制即用,持续更新。

0· 71·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
Name and description (prompt template pack) align with the provided SKILL.md and README; no binaries, env vars, or installs are requested, which is proportional. However, the SKILL.md/README claim 50+ templates and list additional reference files (code-prompts.md, life-prompts.md, code-prompts etc.) that are not present in the file manifest — only writing-prompts.md and business-prompts.md are included. This mismatch between claimed contents and actual files is an inconsistency.
Instruction Scope
SKILL.md contains only prompt templates and instructions to request templates; it does not instruct the agent to read system files, access environment variables, call external endpoints, or transmit data. The instructions stay within the stated domain (generate and explain prompts). Note: '持续更新' (ongoing updates) is claimed but no update mechanism or remote endpoint is provided, so it's unclear how updates would occur.
Install Mechanism
No install spec and no code files — instruction-only skill. This minimizes installation risk (nothing is written/executed on disk).
Credentials
No required environment variables, credentials, or config paths are declared or referenced in instructions — proportional for a prompt/template pack.
Persistence & Privilege
always is false and the skill is user-invocable (normal). disable-model-invocation is false (default autonomous invocation allowed). There is no request to modify other skills or persistent agent settings.
What to consider before installing
This skill looks like a straightforward pack of prompt templates and does not ask for credentials or install anything, but there is a clear inconsistency: the README/SKILL.md claim 50+ templates and additional reference files that are not present in the package. Before installing or relying on it, consider: 1) Verify the author/source or request the missing reference files (code-prompts.md, life-prompts.md) if you need the full 50+ templates. 2) If you expect ongoing updates, ask how updates are delivered (there's no homepage or update mechanism). 3) Inspect the actual templates you will use to ensure they don't include sensitive examples you might copy into external systems. If you cannot confirm the missing files or source, treat the package as incomplete and weigh whether you want to rely on it.

Like a lobster shell, security has layers — review code before you run it.

latestvk97bej8fn2eeqp8d2zdzcaxg7s83z70m

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Comments