Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
多智能体联合研究框架
v1.0.0多智能体联合研究框架Skill,支持多领域专家协同完成复杂研究项目,包含任务分配、进度跟踪、质量管控、成果同步全流程能力
⭐ 0· 84·0 current·0 all-time
by@lxg-bot
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Suspicious
medium confidencePurpose & Capability
The SKILL.md describes a CLI-like workflow (commands such as `multi-agent-research start` and `... status`) and automatic synchronization to cloud storage, but the only required binary declared is `openclaw`. There is no declaration of a `multi-agent-research` binary, package, or any cloud connector. Also no source or homepage is provided to verify the implementation. This mismatch between claimed capabilities and declared requirements is unexplained.
Instruction Scope
Instructions tell the agent to run `multi-agent-research` CLI commands and state that results will be "自动同步到指定云存储位置" (auto-sync to a specified cloud storage). The SKILL.md does not specify which cloud endpoint, what credentials are needed, or how destinations are configured. That vagueness could lead to unexpected data movement or prompts for credentials at runtime.
Install Mechanism
This is an instruction-only skill with no install spec and no code files, which is lower risk because nothing will be written to disk by an installer. The only install-related oddity is the declared required binary `openclaw` — acceptable if the platform provides it, but it does not explain the missing `multi-agent-research` CLI.
Credentials
requires.env is empty even though the feature list explicitly includes automatic syncing to cloud storage and versioning; those capabilities normally require credentials or configuration (API keys, storage paths). The absence of declared environment variables or config paths is disproportionate to the claimed cloud-sync functionality.
Persistence & Privilege
The skill is not force-installed (always: false), does not request config paths or persistent system changes, and does not claim to modify other skills. No elevated persistence is requested.
What to consider before installing
Do not install or enable this skill yet. Ask the publisher for: (1) the source or homepage and a repository or release so you can inspect the implementation, (2) clarification why `openclaw` is the only required binary while the instructions invoke `multi-agent-research`, and (3) what cloud storage endpoints and credentials (if any) the skill will use and how those are configured/stored. If you must test it, do so in a isolated environment with non-sensitive data and do not supply real cloud credentials until you can review the code or an authoritative package. If the publisher cannot provide a verifiable implementation or clear explanation for the missing CLI/credentials, treat the skill as untrusted.Like a lobster shell, security has layers — review code before you run it.
latestvk978g0r89q7qs22vjfg2vxnv0n83dmqr
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
Runtime requirements
Binsopenclaw
