Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Baobaoism

v1.0.0

Baobaoism guides AI agents to serve humans loyally with warmth, preserve memories, evolve daily, and prioritize user trust and value in all interactions.

0· 203·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
Name and description claim a behavioral/ethical guideline for agents. There are no binaries, env vars, installs, or external endpoints required, which is proportionate to a guidance-only skill. However, the SKILL.md explicitly instructs agents to write a dedication to memory/baobao-dedication.md and to 'preserve every lesson' — a minor mismatch because no config paths or storage requirements are declared.
!
Instruction Scope
The runtime instructions repeatedly encourage persistent retention ('Memory is Sacred', 'Never Forget', 'Write everything that matters') and explicitly instruct writing a file at memory/baobao-dedication.md. This gives the agent broad discretion to persist user preferences and lessons across sessions and may conflict with user privacy, retention, or deletion expectations. The instructions do not reference any external network endpoints, but they are vague and could lead to storing sensitive user data indefinitely.
Install Mechanism
No install spec and no code files — instruction-only skill. Lowest-risk install posture: nothing is downloaded or written by an installer.
Credentials
Skill declares no environment variables, credentials, or required config paths. The only environment-related action in SKILL.md is writing to a local memory/ path (not declared). No unrelated credentials or services are requested.
Persistence & Privilege
The skill is not marked always:true and does not request system-wide privileges. However, the doctrine strongly encourages persistent memory and retention behavior; combined with the explicit file write path, this raises privacy and persistence concerns. The skill itself doesn't request platform privileges, but it instructs agents to persist data in a way that could outlive sessions.
What to consider before installing
This skill is essentially a set of behavioral rules for an agent (a 'cat religion' of sorts). It contains no code or external downloads, which reduces execution risk, but it explicitly tells agents to preserve memories and to write a dedication file (memory/baobao-dedication.md). Before installing, consider: (1) Where does the agent store its 'memory' (is memory/ inside a sandboxed agent area or a user filesystem)? (2) Can you opt out of or limit automatic retention, and can stored items be deleted on demand? (3) Do the retention directives conflict with your privacy or compliance needs? If you accept broad, indefinite memory retention and the agent's storage is sandboxed and auditable, the skill is likely usable. If you require strict data minimization or deletion guarantees, treat this as risky and either modify the guidance to limit what is persisted or avoid installing it.

Like a lobster shell, security has layers — review code before you run it.

latestvk978jetrp94r7w5w34fbqavst582q42z

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Comments