HiLegal Boundaryless · Strategic · Results

v1.0.0

This skill should be used when users ask about cross-border compliance, overseas legal compliance, foreign law research, corporate credit checks, global pric...

0· 75·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Benign
medium confidence
Purpose & Capability
The name, description, and included reference manuals align with a cross-border compliance assistant. The SKILL.md explicitly describes RAG-based retrieval, legal research, corporate credit checks and global price lookups — these match the declared purpose. One minor inconsistency: the skill says it will "call enterprise information query interfaces" and "query price databases" but does not declare any required credentials, endpoints, or connectors; that omission gives the agent broad discretion about how to obtain that data.
Instruction Scope
The runtime instructions stick to compliance workflows (need analysis → knowledge retrieval → analysis → structured output) and reference only the bundled knowledge files for RAG. They also generically instruct calling external corporate-info/price databases but do not specify which endpoints, what data to collect, or how to authenticate — this vagueness could cause the agent to perform arbitrary web/API lookups if allowed. There are no instructions to read local system files or unrelated environment variables.
Install Mechanism
This is an instruction-only skill with no install spec and no code files. That minimizes installation risk: nothing is downloaded or written to disk by the skill itself.
Credentials
The skill requires no environment variables or credentials, which is safe in that it doesn't ask for secrets. However, because it promises corporate credit queries and price-database lookups (usually requiring API keys), the lack of declared credentials is noteworthy: either it expects the agent/platform to provide connectors/credentials, or it will rely on public web search. Users should verify how enterprise data sources will be accessed and ensure any API keys are supplied separately and securely if needed.
Persistence & Privilege
The skill is not force-included (always:false) and is user-invocable. It does not request to modify other skills or agent-wide settings. Autonomous model invocation is allowed by default (disable-model-invocation:false), which is normal platform behavior and not flagged on its own.
Assessment
This skill appears to be what it says: a compliance assistant with a local knowledgebase. Before installing or using it, confirm how it will obtain external commercial data (corporate credit reports, price databases): the SKILL.md mentions calling external APIs but provides no endpoints or credential requirements. If you expect the skill to query paid or restricted services, require that API keys be provided by you via the platform's secure credential storage (not pasted into chat). Also consider: 1) verify the accuracy and recency of the included reference files for your jurisdictions; 2) treat outputs as advisory (the skill itself disclaims legal opinion) and consult qualified counsel for high-risk decisions; 3) if you do not want the agent to perform autonomous web/API lookups, restrict the skill's network access or disable autonomous invocation in your agent settings. If you want a stricter review, provide details about how the platform supplies external data connectors or which enterprise APIs you expect the skill to call.

Like a lobster shell, security has layers — review code before you run it.

LegalTechvk972rcykdhm5cn5qw89jz964rn84ge1rlatestvk972rcykdhm5cn5qw89jz964rn84ge1r

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Comments