Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

军地两用人才智能助手

v1.0.0

军地两用人才智能助手 - 基于经典《军地两用人才之友》的综合性技能培训 Agent。 这是一本涵盖军事、农业、机械、建筑、电器、摄影、篆刻、技艺、烹调、会计、管理等领域的"神书"。 触发场景: - 用户询问军事知识(打坦克、打飞机、防御战斗、进攻战斗等) - 用户咨询农业知识(土壤、种子、肥料、种植技术等) -...

0· 34·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Suspicious
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
Name/description promise a combined military-and-civilian training assistant and the included reference documents and query script implement that purpose — the declared requirements (no env vars, no binaries) are consistent with an instruction-and-reference skill. However, the presence of step‑by‑step tactical and explosive instructions is outside what many users would reasonably expect from a general training assistant and elevates risk.
!
Instruction Scope
SKILL.md and the reference files include actionable, procedural guidance for offensive military actions (e.g., selecting explosive charges, placing charges on tank tracks, lighting fuses, methods for attacking aircraft). The runtime examples show concrete steps for committing violent acts. There are no in-skill guardrails (beyond a brief 'for learning only' disclaimer), no provenance or safety filters, and the instructions give the agent direct license to provide operational tactics — this broad, harmful scope is a concern.
Install Mechanism
Instruction-only skill with no install spec and no network/download install actions; minimal disk footprint (one small script + markdown references). From an install mechanism perspective there is low supply-chain risk.
Credentials
The skill requests no environment variables, credentials, or config paths — requested privileges are minimal and proportionate to a local reference/query skill.
Persistence & Privilege
always is false and the skill does not request elevated platform privileges or persist configuration. It is user-invocable and allows model invocation (the platform default); combined with the harmful content this increases potential blast radius but the skill does not request unusual persistence.
What to consider before installing
This skill's files are internally consistent with its stated goal of covering both military and civilian skills, but it contains explicit, actionable instructions for attacking vehicles and aircraft (for example, step‑by‑step explosive placement and fuse use). Before installing, consider: 1) legal and safety implications — hosting or using a tool that provides operational instructions for violence may violate laws or platform policies; 2) provenance — the source is unknown and there is no author/homepage or vetting; 3) remove or redact any step‑by‑step attack/explosive procedures if your use case is benign (historical/academic), or replace them with high‑level, non‑actionable summaries focused on defense, history, or policy; 4) add enforced guardrails (content filters, explicit refusal to provide operational violent instructions, logging/review of queries) and restrict autonomous invocation for this skill if you must keep it; 5) if you are unsure, do not install it into agents that can act autonomously or have access to external systems. If you want, I can suggest safe edits to the SKILL.md and reference files to keep historical/educational content while removing operationally actionable details.

Like a lobster shell, security has layers — review code before you run it.

latestvk97e48zej1624h65vm0qga6hx584vdwh

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Runtime requirements

🎖️ Clawdis

Comments