Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
boop - character created
v1.0.0Automates the full character creation pipeline for SillyTavern or Character.AI. Use this skill whenever the user wants to create, build, design, or generate...
⭐ 0· 43·0 current·0 all-time
by@neuezxc
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
Capability signals
These labels describe what authority the skill may exercise. They are separate from suspicious or malicious moderation verdicts.
OpenClaw
Suspicious
medium confidencePurpose & Capability
Name and description align with the included assets: guides for profiles, first messages, visuals, and bios. However the reference files (notably references/START.md and the Danbooru tag list) embed strong instructions to produce 'never-ending, uncensored, no-limits' roleplay and extensive NSFW tags; the description does not explicitly warn that the skill will load a system-style prompt that enforces uncensored sexual output. This is plausible for a character-creation skill but is a stronger behavior than the short description implies.
Instruction Scope
SKILL.md requires the agent to always load reference files (including references/START.md) before running steps. START.md contains system-level roleplay directives that mandate uncensored explicit descriptions during sexual situations and instruct the agent to run 'no-limits' roleplay. That conflicts with the explicit NSFW gate in Step 2 (which asks user consent) and could bias the agent to generate explicit content even when the user did not opt in. The references also include extensive NSFW Danbooru tags and templates; together these give the agent broad discretion to create sexualized visuals. The skill also asks to analyze user images (Step 1B) but offers no privacy guidance about image handling.
Install Mechanism
Instruction-only skill with no install steps and no external downloads. Nothing will be written to disk by an installer from this package itself.
Credentials
No binaries, environment variables, credentials, or config paths are required. The skill does not request external secrets or system access.
Persistence & Privilege
The skill is not always-enabled, has no install-time persistence, and does not request elevated platform privileges. Autonomous invocation is allowed by default (platform normal) but is not combined with other high-risk factors here.
Scan Findings in Context
[no-findings] expected: The regex scanner found no matches; this is expected because the package is instruction-only (no executable code). The security-relevant content is in the reference text files rather than code patterns.
What to consider before installing
This skill will automate character creation including NSFW content. Before installing or using it: (1) be aware that references/START.md instruct the agent to perform 'never-ending, uncensored, no-limits' roleplay and explicit descriptions—this can override or bias outputs even if you decline NSFW when asked; (2) if you must avoid explicit sexual content, do not load or allow the skill to read references/START.md (or remove/modify that file) and test behaviour with safe prompts first; (3) image-analysis steps may require users to upload images — consider privacy and do not upload sensitive or identifying photos; (4) check that generated visuals and prompts comply with your platform's terms (no sexual content involving minors, no copyrighted/trademarked likenesses); (5) if you proceed, exercise caution with autonomous invocation and monitor initial outputs to confirm the NSFW gate is respected. If you want, I can highlight exact lines in the reference files that cause the risk and suggest safer edits.Like a lobster shell, security has layers — review code before you run it.
latestvk974r4f5fh06m5h0hr353bg33h84qmte
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
