Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Learn Anything Pro

v1.0.0

提供Learn-Anything.xyz知识图谱中的优质学习资源和路径,涵盖编程、AI、数据科学、理财、加密货币等领域。

1· 346·2 current·2 all-time

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for pxyyqm626529-afk/learn-anything-pro.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "Learn Anything Pro" (pxyyqm626529-afk/learn-anything-pro) from ClawHub.
Skill page: https://clawhub.ai/pxyyqm626529-afk/learn-anything-pro
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Canonical install target

openclaw skills install pxyyqm626529-afk/learn-anything-pro

ClawHub CLI

Package manager switcher

npx clawhub@latest install learn-anything-pro
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
Name and description claim to provide learning paths from Learn-Anything.xyz; the SKILL.md content, supported topics, and response examples align with that purpose. However, the inclusion of pricing and a hard-coded API key in the SKILL.md is outside the core purpose of 'helping learn' and is not declared in the skill metadata.
!
Instruction Scope
SKILL.md is an instruction-only file and does not tell the agent to read local files or request unrelated credentials, which is good. But it explicitly embeds payment instructions and an API key (SkillPay.me API key) in cleartext and does not explain how the key is used, where payments are sent, or whether the agent will contact external payment endpoints — leaving ambiguity about network calls and potential hidden behavior.
Install Mechanism
No install spec and no code files — instruction-only skill. This minimizes installation risk because nothing is written to disk and no external packages are fetched by an automated install step.
!
Credentials
The skill metadata declares no required environment variables or credentials, yet SKILL.md contains an apparent secret API key (sk_...) and pricing details. A hard-coded key in the instructions is disproportionate and inconsistent with the manifest; it is unclear whose key this is and whether the agent will use it or request additional user credentials.
Persistence & Privilege
The skill does not request 'always: true' and uses default invocation settings. It does not declare any persistence or system-wide configuration changes. Autonomous invocation remains possible (platform default), but there is no elevated privilege requested by the skill itself.
What to consider before installing
This skill mostly does what it says (recommends Learn-Anything learning paths), but the SKILL.md contains pricing and a hard-coded API key (SkillPay.me) that are not declared in the metadata. Before installing, ask the publisher: (1) what is that API key for and who owns it; (2) what network endpoints (payment or telemetry) the skill will contact and when; (3) whether the skill will ever request or store your credentials or charge you automatically. If you or your org provided payment keys, do not accept a skill that publishes them in plain text — rotate the key immediately. If the publisher cannot clearly explain the payment flow and why the key is embedded (and provide an alternative such as requiring the integrator to set their own secret via environment variables), treat the skill as untrusted and do not install. Additional information that would raise confidence: explicit declaration of required env vars/primary credential, clear API endpoint URLs for payments, and an explanation of how/when billing occurs.

Like a lobster shell, security has layers — review code before you run it.

latestvk97bxev7hnnv1gjdhta05f0zv582hkw2
346downloads
1stars
1versions
Updated 13h ago
v1.0.0
MIT-0

Learn Anything Pro 专业学习助手

简介

Learn Anything Pro - 专业学习助手,从Learn-Anything.xyz知识图谱获取最优质的学习资源。

功能

  1. 编程学习 - GitHub、Python、JavaScript等编程相关问题
  2. AI与机器学习 - 人工智能、深度学习、机器学习
  3. 提示词工程 - Prompt Engineering最佳实践
  4. 数据科学与分析 - 数据分析、可视化、统计学
  5. 个人理财 - 投资理财、财务规划
  6. 加密货币 - 区块链、DeFi、加密货币投资
  7. YouTube学习 - 优质YouTube教程推荐

定价

  • 费用: 0.001 USDT / 每次调用
  • 支付方式: SkillPay.me
  • API Key: sk_3bf4e74479614724623768f5269c68251b09adf555a891eda68dbdfeac108f01

使用方法

提问示例

我想学习Python编程
什么是深度学习?
如何学习提示词工程?
推荐一些数据分析的教程
学习加密货币投资从哪里开始?
给我介绍GitHub的使用方法

数据来源

所有学习资源来自 Learn Anything - 全球最大的知识图谱之一,汇集了各领域专家推荐的最优质学习资源。

支持的话题

  • 编程开发:Python, JavaScript, Git, GitHub, React, Node.js, SQL等
  • 人工智能:AI, Machine Learning, Deep Learning, NLP, Computer Vision等
  • 数据科学:数据分析, 数据可视化, 统计学, R, Pandas等
  • 个人理财:投资, 理财, 股票, 基金, 退休规划等
  • 加密货币:区块链, 比特币, 以太坊, DeFi, NFT等
  • 提示词工程:Prompt Engineering, ChatGPT提示词, AI提示技巧等

响应示例

根据您的问题,我会从Learn-Anything.xyz知识图谱中提取相关的学习路径和资源,包括:

  • 最佳学习路线
  • 推荐教程和课程
  • 必备工具和资源
  • 实践项目建议
  • 相关话题延伸

风险提示

本服务仅提供学习资源推荐,不构成任何投资建议。加密货币投资有风险,请谨慎操作。

版本

  • v1.0.0 - 初始版本

Comments

Loading comments...