Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Social Brand Voice

v1.0.0

Brand voice guide creator for social media. Define your brand's tone, vocabulary, writing rules, and examples across platforms — so every post sounds consist...

0· 102·0 current·0 all-time
Security Scan
VirusTotalVirusTotal
Suspicious
View report →
OpenClawOpenClaw
Benign
medium confidence
Purpose & Capability
Name/description (brand voice guide) matches the behavior: the script builds a prompt and asks an agent to generate a multi-part brand voice guide. Nothing in the code suggests functionality beyond content generation.
Instruction Scope
analyze.sh constructs a full prompt from the user's input and runs 'openclaw agent --local ...' to produce the guide, then formats output with python3. The script does not read arbitrary files, environment variables, or external hard-coded endpoints. Note: all user-provided input is forwarded to the agent invocation — avoid sending secrets.
Install Mechanism
No install spec (instruction-only plus a helper script). No downloads or archive extraction. Nothing writes to system paths or attempts to install third-party code.
!
Credentials
The skill declares no required binaries or env vars, but analyze.sh invokes the 'openclaw' CLI and 'python3' at runtime. The missing declared requirements is an inconsistency. Also, while no credentials are requested by the skill, the openclaw agent will run using whatever agent configuration/credentials exist on the host — that could cause user input to be sent to a remote model provider depending on the user's OpenClaw configuration.
Persistence & Privilege
always:false and the skill does not modify system or other-skill configs. It does not request persistent presence or elevated privileges.
Assessment
This skill appears to do what it says (generate a brand voice guide) and contains a small helper script that invokes your OpenClaw agent. Before installing or running it: 1) Confirm you have the openclaw CLI and python3 available (the metadata doesn't list them but analyze.sh requires them). 2) Review and avoid passing any sensitive secrets or private customer data to the script — the input is forwarded to your agent and may be sent to whatever model endpoint your OpenClaw configuration uses. 3) If you want clearer safety, ask the publisher to add required-binaries (openclaw, python3) to the metadata and to document whether the agent runs completely locally or contacts a hosted API. 4) If you are uncertain about where your data will go, run the script in an isolated environment or with dummy inputs first.

Like a lobster shell, security has layers — review code before you run it.

latestvk975f7zn93n5t8pakxj64pbaps83fcwm
102downloads
0stars
1versions
Updated 3w ago
v1.0.0
MIT-0

Social Brand Voice

Build a complete brand voice guide so your content always sounds like YOU.

Usage

brand voice: DTC skincare brand targeting millennial women
tone of voice: B2B fintech startup professional but approachable
brand guide: personal brand for senior software engineer
voice guide: outdoor adventure e-commerce brand fun and bold

What You Get

  1. 4 Voice Dimensions — personality traits with do/don't examples
  2. Tone Spectrum — where you sit on 5 key tone axes
  3. Vocabulary Guide — words to use and words to ban
  4. Platform Voice Variants — how the voice adapts per platform
  5. Before/After Examples — rewrites showing voice in action
  6. Quick Reference Card — one-page cheat sheet for your team

Comments

Loading comments...