Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Agent Team Organization

v1.0.1

Create and maintain a Teams management page for OpenClaw Control UI, including named agent teams, parent/child nesting, indented tree rendering, collapsible...

0· 117·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Suspicious
View report →
OpenClawOpenClaw
Benign
high confidence
Purpose & Capability
Name/description describe a Teams UI and file-backed registry; the SKILL.md, data model, registry path (~/.openclaw/workspace/teams/teams.json), gateway methods, and UI file map all align with that purpose. No unrelated binaries or environment variables are requested.
Instruction Scope
Instructions stay on-topic (UI, gateway RPCs, JSON registry). They explicitly direct the operator to read and write the registry file and to inspect compiled runtime bundles. The guidance to 'patch the active bundle if necessary' and to restart the gateway implies modifying live runtime artifacts and requires elevated filesystem/process permissions; this is plausible for a developer-facing troubleshooting guide but should be performed only by trusted operators and with backups.
Install Mechanism
Instruction-only skill with no install spec and no external downloads or binaries. Lowest-risk installation footprint.
Credentials
No environment variables, credentials, or external service tokens are requested. File paths referenced (user workspace JSON) are appropriate for a local registry feature and consistent with the described functionality.
Persistence & Privilege
Skill is not forced-always and can be invoked by users. It does not request persistent privileges or modify other skills' configs. The recommended operational steps (rebuild, restart gateway, patch bundle) imply system-level actions but are described as part of a developer workflow rather than automatic behavior.
Assessment
This skill is coherent with building and debugging a Teams UI backed by a local JSON registry. Before using the troubleshooting steps that touch runtime bundles or patch active artifacts, ensure you have appropriate system access, a backup of the compiled bundle and teams.json, and that only trusted operators perform live bundle edits and gateway restarts. Confirm file permissions and consider testing rebuilds in a staging environment rather than patching production bundles directly.

Like a lobster shell, security has layers — review code before you run it.

latestvk971vz35rha0v5mrzews4zfeqx833ajd

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Comments