Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Suspicious
high confidencePurpose & Capability
The name/description claim this is a 'Scholarship' assistant (rules, deadlines, application tips), but SKILL.md describes filtering by learning stage/teaching form/assessment metrics and returning fields like learning time,错题本同步 (error-book sync), mock exam scores, course downloads and instructor résumés — functionality more appropriate for a learning platform or course manager, not a scholarship advisor. This mismatch is unexplained.
Instruction Scope
The SKILL.md instructs the agent to surface user-correlated data (learning time accumulation, error-book sync, mock exam scorecards, download progress, 学历认证关联) which implies access to personal learning records and files. However the skill declares no mechanisms, access methods, or permissions for those data sources. The instructions are also broad/vague (no precise endpoints or data boundaries), leaving wide discretion to gather unspecified context.
Install Mechanism
No install spec and no code files — the skill is instruction-only, which minimizes direct installation risk (nothing will be written to disk by the skill itself).
Credentials
The skill declares no required environment variables or credentials, yet the instructions imply accessing user-specific learning data and syncing state. Either the skill cannot actually perform the listed returns, or it will require additional credentials/access that are not declared — this is a proportionality/information gap.
Persistence & Privilege
Skill flags are default (not always:true). There is no install-time persistence requested and no evidence it modifies other skills or system-wide settings.
What to consider before installing
This skill is internally inconsistent: it claims to help with scholarships but its runtime instructions read like a course/learning platform assistant that wants to read and sync personal learning data. Before installing, ask the publisher for: (1) a clear statement of purpose and example interactions that match that purpose; (2) what data sources the skill will access and what credentials/permissions are required; (3) a homepage or source repository and a contact for support; and (4) a privacy statement explaining how personal learning records (错题本, mock scores, downloads) are accessed, stored, or transmitted. If the author cannot clarify why scholarship functionality needs access to user learning records, treat the skill as untrusted and do not grant it access to sensitive accounts or files.Like a lobster shell, security has layers — review code before you run it.
latestvk97bt5s64hx3pktwkq94jwp3ns837115
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
