Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
Markdown Editor With Chat
v1.1.2Lightweight markdown editor with optional OpenClaw gateway chat. Filesystem-based, no database required.
⭐ 0· 746·3 current·3 all-time
byVladimir Orany@musketyr
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Benign
high confidencePurpose & Capability
The name/description (filesystem markdown editor with optional gateway chat) aligns with the files and runtime: node is required, MARKDOWN_DIR is required, and the server implements file listing, reading, writing, and an optional chat proxy. No unrelated binaries or credentials are requested.
Instruction Scope
SKILL.md instructs running the provided Node server with a folder argument or MARKDOWN_DIR; the runtime instructions and APIs in server.mjs stay within that scope (serve UI, list/get/save .md files, proxy chat). The server implements path traversal protection and blocks dotfiles and non-.md files.
Install Mechanism
There is no install spec (instruction-only skill besides bundled source). No external downloads or package installs are requested. The only runtime dependency is the node binary (no npm modules), which is proportional for a pure-Node script.
Credentials
Only MARKDOWN_DIR is required; OPENCLAW_GATEWAY_URL and OPENCLAW_GATEWAY_TOKEN are optional and relevant only for the chat proxy feature. The declared sensitive env var (gateway token) matches its use. No unrelated secrets or multiple external credentials are requested.
Persistence & Privilege
The skill does not request always:true and does not modify other skills or system-wide settings. It runs a local HTTP server and stores files only under the supplied MARKDOWN_DIR, which is consistent with its purpose.
Assessment
This package appears to be what it says: a local markdown editor that serves files from a directory and can optionally proxy chat requests to an OpenClaw gateway. Before installing/running, consider the following:
- Set MARKDOWN_DIR to a directory you control and do not point it at system or secret-bearing directories (e.g., /, /root, ~/.ssh). The server will read and write files under that directory.
- If you enable chat, the server will make outbound requests to OPENCLAW_GATEWAY_URL using OPENCLAW_GATEWAY_TOKEN; the token is sent only by the server (not exposed to the browser) but you should ensure the gateway endpoint is trusted.
- The server enforces a localhost/private-host binding by default, but verify you run it on a safe host and do not deliberately expose it to the public internet.
- The code uses the Node global fetch API — run with a modern Node.js (Node 18+).
If you need higher assurance, you can review the complete scripts/server.mjs and index.html (both included) locally before running; otherwise running it in an isolated environment (e.g., a throwaway VM or container) is a reasonable precaution.Like a lobster shell, security has layers — review code before you run it.
latestvk9758067t1j8rpnakwc4exjq5981m9gj
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
Runtime requirements
📝 Clawdis
Binsnode
EnvMARKDOWN_DIR
