Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Google Maps B2B Lead Goldmine

v1.0.0

Extract, score, and export detailed local business leads from Google Maps by keyword and location with contact info, reviews, and personalized outreach messa...

0· 46·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
The skill's name/description (scraping Google Maps, extracting contact details, scoring leads) aligns with the runtime instructions which call Apify actors and crawl business websites. Using Apify actors and a lead-scoring function is coherent with the advertised capability.
Instruction Scope
SKILL.md explicitly instructs the agent/operator to create an Apify account, export APIFY_TOKEN, install npm packages, and run Apify actors to scrape data and crawl websites. Those steps stay within the stated purpose (scraping, enrichment, outreach generation). However the doc also references 'Claude AI' for personalization without specifying how to provide Claude credentials or exactly when/where Claude is invoked — that is an ambiguous scope expansion.
Install Mechanism
This is an instruction-only skill (no install spec, no code files). The README recommends running 'npm install apify-client axios' locally — a normal, low-risk developer instruction. There is no packaged install that would download arbitrary archives or create persistent binaries.
!
Credentials
Registry metadata declares no required env vars or primary credential, but SKILL.md instructs the user to set APIFY_TOKEN (and mentions Claude AI). The skill therefore requires credentials that are not declared in the metadata. That mismatch is a proportionality / transparency problem: an Apify token is required for core functionality and should be listed; any AI service credentials used for personalization should also be declared.
Persistence & Privilege
The skill does not request 'always: true' and is user-invocable only. It is instruction-only and does not declare actions that modify other skills or system-wide settings. Autonomous invocation is allowed by default but not a new privilege here.
What to consider before installing
This skill appears to do what it says (use Apify to scrape Google Maps and enrich leads), but there are two practical issues to weigh before installing/using it: - Missing credential declaration: The registry metadata lists no required env vars, yet SKILL.md requires you to export an APIFY_TOKEN and hints at using Claude AI. Treat that as a red flag — ask the publisher to update metadata so you know exactly what secrets you'll need to provide. - Privacy, legality and terms-of-service: Scraping Google Maps and extracting contact details and emails can violate Google/website terms of service and may involve personal data. Confirm you have the right to collect and use this data, and check Apify and Google terms and any regional privacy rules (e.g., GDPR). - Operational safety: The README recommends installing npm packages and invoking third-party Apify actors. Only install dependencies you trust, verify the actor IDs/owners (e.g., 'compass~crawler-google-places' vs 'apify/website-content-crawler') to ensure you are calling legitimate actors, and monitor billing/usage on your Apify account. - Mitigations: Use a dedicated Apify account and a token with limited permissions; do not reuse high-value credentials. Ask the skill author for an explicit list of required env vars and any external endpoints the skill will contact (including where personalization via 'Claude AI' runs and what credentials it needs). If the author cannot or does not provide clear metadata and source, treat the skill as higher risk and avoid providing long-lived or privileged secrets.

Like a lobster shell, security has layers — review code before you run it.

agenciesvk977nrnbt8f5zt6hqshfzvxxnh83syq1apifyvk977nrnbt8f5zt6hqshfzvxxnh83syq1cold-emailvk977nrnbt8f5zt6hqshfzvxxnh83syq1instantlyvk977nrnbt8f5zt6hqshfzvxxnh83syq1latestvk977nrnbt8f5zt6hqshfzvxxnh83syq1lead-generationvk977nrnbt8f5zt6hqshfzvxxnh83syq1lemlistvk977nrnbt8f5zt6hqshfzvxxnh83syq1outreachvk977nrnbt8f5zt6hqshfzvxxnh83syq1

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Comments