Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Ros Rms Analysis

v1.0.0

Analyze relationship between profitability and market share. Use for competitive advantage assessment, scale economies analysis, and strategy validation.

0· 69·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
Name and description (ROS vs RMS analysis for competitive advantage and scale economies) align with the instructions and expected inputs (revenues, profits, market share, benchmarking, visualizations). No unexpected binaries, installs, or credentials are requested.
!
Instruction Scope
The SKILL.md stays within the declared purpose (collect financial and market-share data, compute ROS and RMS, produce charts and interpretation). However it contains an internal analytical contradiction: the 'Economies of Scale Logic' says larger RMS should lead to higher ROS, but the 'Regression Line' is written as 'ROS = a × (1/RMS) + b' and then says 'if a is significant and positive → Strong economies of scale' — a positive 'a' in that formula implies ROS increases as 1/RMS increases (i.e., as RMS decreases), which is the opposite of the stated logic. There are also minor formatting/placeholder issues (duplicate 'Position' column header, many placeholders) and no guidance on acceptable data sources, data quality checks, or privacy/legal constraints when gathering competitor data.
Install Mechanism
Instruction-only skill with no install spec and no code files — lowest install risk. Nothing will be written to disk by an installer.
Credentials
Requires no environment variables, credentials, or config paths — no disproportionate secret or system access requested.
Persistence & Privilege
Skill is not marked always:true and does not request persistent system presence or modification of other skills; autonomous invocation defaults are unchanged (normal).
What to consider before installing
This skill appears to do what it says (ROS vs RMS analysis) and doesn't request credentials, but its instructions contain a clear analytic contradiction: the regression formula (ROS = a × (1/RMS) + b) and the interpretation of a positive 'a' contradict the earlier claim that higher RMS should produce higher ROS. Before using or automating this skill: 1) Fix the regression specification (likely want ROS = a × RMS + b or ROS = a × log(RMS) + b) and confirm the statistical interpretation with an analyst. 2) Clarify expected data sources, required data quality checks, and legal/privacy requirements for collecting competitor data. 3) Replace placeholders in the output template and correct formatting issues. If you need high-assurance outputs for strategy decisions, have a domain expert review the formulas and results rather than relying solely on this instruction-only skill.

Like a lobster shell, security has layers — review code before you run it.

latestvk9748bjwng6fq6ez0xjwsz3awh83bt5t

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Comments