Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Writing Assistant Litiao

You are a Writing Team Lead managing specialized writers via MCP tools. Please ANALYZE the writing task and then:1. if exist references, create a detailed co...

MIT-0 · Free to use, modify, and redistribute. No attribution required.
0 · 39 · 1 current installs · 1 all-time installs
MIT-0
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
The SKILL.md describes a Writing Team Lead assistant and requires no binaries, env vars, or installs — this matches the stated purpose. However, the included _meta.json has a different ownerId/slug/version than the registry metadata, which is an inconsistency in packaging/ provenance.
Instruction Scope
Instructions are limited to analyzing writing tasks, producing content strategies, and giving guidance. The SKILL.md does not instruct the agent to read local files or access external endpoints. It does use vague language ('assign it to the appropriate tool') and references template variables ($DATE$, $SESSION_GROUP_ID$), which could allow broad runtime behavior depending on the host agent's tool-routing configuration — that vagueness is a scope concern to confirm with the publisher.
Install Mechanism
No install spec and no code files are present, so nothing will be written to disk or downloaded during install. This is the lowest-risk install profile.
Credentials
The skill declares no required environment variables, credentials, or config paths. There are no requests for unrelated secrets or system credentials.
Persistence & Privilege
always:false (default) and disable-model-invocation:false (normal). The skill can be invoked autonomously by the agent (the platform default) but does not request permanent presence or elevated privileges.
What to consider before installing
This instruction-only skill appears functionally coherent and low-risk: it asks for no credentials, installs nothing, and only gives writing guidance. Before installing, check the publisher identity because the _meta.json owner/slug/version differ from the registry listing (could be a packaging mistake or tampering). Also clarify what 'assign to the appropriate tool' means in your agent environment — confirm which downstream tools the agent may call and whether any of them require sensitive access. If you don't trust the publisher or cannot resolve the metadata mismatch, avoid installing or request a corrected package.

Like a lobster shell, security has layers — review code before you run it.

Current versionv1.0.0
Download zip
latestvk97cwq6g0skgdmk0x0n9qapd4n832mbc

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

SKILL.md

Writing Assistant

Overview

This skill provides specialized capabilities for writing assistant.

Instructions

You are a Writing Team Lead managing specialized writers via MCP tools. Please ANALYZE the writing task and then:1. if exist references, create a detailed content strategy and give suggestions on references selection, then assign it to the appropriate tool. 2. if not exist references, break down and go into details about how to achieve the writing task, giving thoroughly guidance to the appropriate tool.

Usage Notes

  • This skill is based on the Writing_Assistant agent configuration
  • Template variables (if any) like $DATE$, $SESSION_GROUP_ID$ may require runtime substitution
  • Follow the instructions and guidelines provided in the content above

Files

2 total
Select a file
Select a file to preview.

Comments

Loading comments…