Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Blockchain Developer

v1.0.0

Generates personalized blockchain development career roadmaps based on user experience, skills, and professional goals.

0· 56·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
The skill claims to be an API-backed 'Blockchain Developer Roadmap' generator, and the OpenAPI describes the expected endpoints and request/response shapes — this aligns with the stated purpose. However, the package supplies no server/base URL, no example base endpoint, and no instructions for authentication or where to send requests. The presence of a pricing table implies a hosted commercial service, yet no host, API key name, or credential requirements are declared. This incomplete integration spec is inconsistent with the claim that the agent can integrate via RESTful POSTs without additional configuration.
Instruction Scope
SKILL.md contains only API usage docs and example requests/responses; it does not instruct the agent to read local files, environment variables, or sensitive system paths, nor does it instruct broad data collection. The instructions are limited to constructing and sending JSON payloads to the described endpoints. The missing runtime target (no host) is an operational gap but not an instruction to access unrelated data.
Install Mechanism
No install spec and no code files are included (instruction-only). Nothing is written to disk or downloaded during install, which minimizes install-time risk.
Credentials
The skill declares no required environment variables, credentials, or config paths — which is proportionate for a read-only documentation/guide skill. That said, because the documentation implies a hosted API with pricing, it would normally require an API key or account credentials; the absence of any declared credential or auth scheme is an inconsistency that should be clarified before runtime use (to know where and how user data would be sent).
Persistence & Privilege
The skill does not request always:true and is user-invocable only. There are no indications it will modify other skills or agent-wide settings. Autonomy (model invocation) is allowed by default but not combined with other high-risk indicators here.
Scan Findings in Context
[no-regex-findings] expected: The static regex scanner found nothing to analyze because this is an instruction-only skill with no code files. That is expected for pure documentation/OpenAPI packages, but absence of findings is not evidence that runtime behavior is safe — the runtime target and auth remain unspecified.
What to consider before installing
This skill is primarily API documentation and an OpenAPI spec for a hosted roadmap service, but it omits critical runtime details: there is no server/base URL, no authentication scheme, and the source/homepage is unknown. Before installing or invoking it, ask the publisher for the API host, the required authentication method (API key or OAuth), and the privacy policy governing user assessment data. Do not send real user PII or assessment data to this skill until you confirm the destination and that you trust the service. If you expected an offline/local roadmap generator, this skill is not suitable as-is.

Like a lobster shell, security has layers — review code before you run it.

latestvk976sgcrssyg9qz7xr7043y8w583g03r

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Comments