Email Cold Zh

Security checks across static analysis, malware telemetry, and agentic risk

Overview

This is an instruction-only Chinese cold-email drafting skill with no code, install steps, credentials, or sending capability; the only notable point is its generic request for read/write tools.

This skill appears safe for drafting cold outreach copy. Review generated claims for accuracy and legal/compliance requirements, and only allow it to read or write specific files if you intentionally provide context or want to save a draft.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Risk analysis

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

#
ASI02: Tool Misuse and Exploitation
Low
What this means

If granted, the agent could read from or write to local files while helping draft emails, even though no automatic or broad file operation is shown.

Why it was flagged

The skill requests generic file read/write tools even though its main purpose is email text generation. This is not suspicious by itself, but users should notice and scope any file access.

Skill content
## Tools Required
- read
- write
Recommendation

Use the skill interactively and approve only specific file reads or draft-file writes that are needed for the email task.