Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
Attic Ventilation Video
v1.0.0AI video creation for attic ventilations, wealth management practices, independent financial planners, and registered investment advisors — generate retireme...
⭐ 0· 49·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
Capability signals
These labels describe what authority the skill may exercise. They are separate from suspicious or malicious moderation verdicts.
OpenClaw
Suspicious
medium confidencePurpose & Capability
The skill is titled and keyworded around 'attic ventilation' but the SKILL.md content is almost entirely focused on financial-planning marketing videos for advisors (retirement, Social Security, rollovers, fiduciary messaging, etc.). There are no required env vars or binaries that would explain cross-domain needs, so the mismatch appears to be either a labeling/SEO error or keyword stuffing rather than coherent purpose-capability alignment.
Instruction Scope
SKILL.md is instruction-only and describes generating many kinds of financial-education and marketing videos. The instructions (as provided) do not tell the agent to read filesystem paths, environment variables, or external endpoints beyond normal content generation. However, the content scope includes regulated financial advice topics — the skill could prompt users for sensitive client financial details in normal use, so operators should avoid supplying real PII or client data without compliance review.
Install Mechanism
No install spec and no code files are present (instruction-only). This minimizes technical risk: nothing will be downloaded or written to disk by the skill itself during install.
Credentials
The skill declares no required environment variables, credentials, or config paths. There is no apparent request for sensitive credentials. That said, the skill's functional scope (financial advice/marketing) may lead it to ask for user-supplied financial details at runtime — those would be sensitive and should be treated separately from environment variables.
Persistence & Privilege
The skill does not request always:true and uses default invocation settings (user-invocable, autonomous invocation allowed). It does not declare permissions to modify other skills or system-wide agent settings.
What to consider before installing
This skill is instruction-only and technically low-risk (no installs or required credentials), but there is a clear mismatch between the skill name/keywords (attic ventilation) and the actual instructions (financial-planning video creator). Before installing or using it: 1) Ask the publisher why the name/keywords reference 'attic ventilation' and confirm the intended domain. 2) Do not provide real client PII or financial account credentials when testing — the skill may ask for case-specific financial details that are sensitive. 3) If you plan to use generated content for client-facing advice, get a compliance/legal review (financial advice is regulated). 4) Prefer testing in a sandbox account and review outputs for accuracy and privacy leaks. 5) If the naming mismatch is unexplained, treat this as a red flag (possible mislabeling or keyword stuffing) and consider not installing until clarified.Like a lobster shell, security has layers — review code before you run it.
latestvk97dswk0hpewaqz359gwdrdxns84eyy2
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
