Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
Compliance Management
v1.0.0Multi-framework compliance assessment and management system for evaluating organizational adherence to security and regulatory standards.
⭐ 0· 56·0 current·0 all-time
byToolWeb@krishnakumarmahadevan-cmd
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Suspicious
medium confidencePurpose & Capability
The SKILL.md and openapi.json present a networked Compliance Management API (endpoints for assessments, frameworks, controls). A networked API integration normally requires a base URL and authentication (API key, token, or similar). This skill declares no required environment variables, no server URL, and no install or hosting details — which is inconsistent with the stated purpose of acting as an external API client or wrapper.
Instruction Scope
The runtime instructions and examples are scoped to submitting assessment payloads and returning assessment results. They do not instruct the agent to read unrelated local files, scan system configuration, or exfiltrate other data. No instructions request unrelated environmental context.
Install Mechanism
This is an instruction-only skill with no install spec and no code files executed on the host. That reduces disk-execution risk. The included openapi.json is a spec file only and contains no server entries.
Credentials
A multi-framework API normally needs credentials and a target server. The skill requests no environment variables, no primary credential, and no config paths. That absence is disproportionate to an API integration and leaves unclear where requests would be sent and what auth (if any) would be used. The missing credential requirements are a notable gap.
Persistence & Privilege
The skill is not marked always:true and does not request persistent system-wide configuration or privileges. It appears to be an on-demand, user-invocable instruction-only skill.
What to consider before installing
This skill describes a remote Compliance Management API but provides no server URL, no authentication requirements, and no source/homepage. Before installing or using it: (1) Ask the publisher for the API base URL, auth method (API key/OAuth), and hosting domain; do not supply sensitive org data until you confirm the destination and TLS/ownership. (2) Prefer skills that declare required env vars (API_KEY, BASE_URL) and list a trusted source or homepage. (3) If you must test it, do so with non-sensitive, synthetic data in a sandbox. (4) If the agent ever asks to send real configuration or credentials to an unspecified endpoint, deny and investigate — that is the primary risk here.Like a lobster shell, security has layers — review code before you run it.
latestvk977pb6nzwt59s7rcsqsk15fyd83vt30
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
