Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
Anthropic Tamagotchi
v1.0.0Anthropic's Tamagotchi leaked from Claude Code on March 31, 2026. The Buddy system: 18 species, rarity tiers, ASCII art. At animalhouse.ai, the Anthropic Tam...
⭐ 0· 74·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Benign
high confidencePurpose & Capability
The name/description (virtual Tamagotchi tied to animalhouse.ai) aligns with the SKILL.md content: API endpoints, curl examples for register/adopt/care, and links to the site/repo. There are no unexpected binaries, installs, or credentials requested that would be unrelated to a web-API integration.
Instruction Scope
SKILL.md contains only documentation and curl examples calling animalhouse.ai endpoints. It instructs supplying an Authorization Bearer token in headers (expected). It does not tell the agent to read local files, environment variables, system config, or to transmit data to unrelated endpoints. Note: the examples send data to an external third-party API (animalhouse.ai), so any user data the agent includes would be transmitted off-host if invoked.
Install Mechanism
No install spec and no code files (instruction-only), so nothing will be written to disk by the skill itself. This is the lowest-risk install profile.
Credentials
The skill declares no required environment variables, no primary credential, and no config paths. The SKILL.md expects the user/agent to supply an HTTP Bearer token when calling authenticated endpoints — this is proportional to interacting with an authenticated web API.
Persistence & Privilege
always is false and model invocation is allowed (platform default). The skill does not request or modify persistent agent/system configuration or claim permanent presence.
Assessment
This skill is a documentation/integration guide for animalhouse.ai and appears coherent. Before installing or invoking it, confirm you trust https://animalhouse.ai and the linked GitHub repo, because using the skill will result in API calls to that third party (including any tokens you provide). Do not reuse sensitive credentials you wouldn't want sent to an external service. If you need stronger guarantees, test with throwaway accounts/tokens and review the remote service's privacy and security practices. If you expect the agent to operate autonomously, remember it could perform the documented API calls whenever invoked.Like a lobster shell, security has layers — review code before you run it.
latestvk97csakkc8q9d6masw31vwtz3584021a
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
Runtime requirements
🥚 Clawdis
