Upwork Automation Gig

AdvisoryAudited by Static analysis on Apr 30, 2026.

Overview

No suspicious patterns detected.

Findings (0)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

The agent could submit proposals that affect your professional reputation, platform account, and potential commitments.

Why it was flagged

The skill tells the agent to generate a proposal and apply after a broad user request to find jobs, without requiring the user to review or approve each application.

Skill content
當用戶話「搵job」既時候:... 3. 生成proposal apply
Recommendation

Use draft-only behavior by default and require explicit confirmation for each proposal or message before submission.

What this means

Unreviewed outreach could look spammy, contact the wrong people, or create business/reputation risk on the user's behalf.

Why it was flagged

Automatic outreach to potential clients is a high-impact communication action, and the artifact does not define recipient limits, rate limits, content review, or opt-in boundaries.

Skill content
Outreach - 自動send message俾潜在客戶
Recommendation

Require user-selected recipients, message preview, explicit send approval, and clear limits on volume and frequency.

ConcernMedium Confidence
ASI03: Identity and Privilege Abuse
What this means

The agent may need to act under the user's marketplace identity without clear limits on what account actions are allowed.

Why it was flagged

Applying on Upwork/Fiverr normally requires logged-in account authority, but the artifacts do not declare a credential flow, scope, or authorization boundary.

Skill content
去Upwork/Fiverr search相關關鍵詞 ... 生成proposal apply
Recommendation

Declare the account access method, avoid using stored cookies or sessions implicitly, and restrict the skill to user-approved actions.

What this means

Your job leads, application history, and status notes may be retained or reused by the agent.

Why it was flagged

Tracking applied jobs and statuses is purpose-aligned, but the artifact does not say where this data is stored, how long it is retained, or whether it can be deleted.

Skill content
Lead Tracking - 記錄你apply過既job同status
Recommendation

Clarify storage location, retention, deletion, and whether tracked leads are reused across future tasks.