Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Caveman Soul Optimizer

v1.0.0

Compresión de razonamiento interno para agentes de OpenClaw. Ahorra tokens en procesos de planificación y análisis ("Chain of Thought"). PRESERVA INTEGRALMEN...

0· 78·1 current·1 all-time
byRicardo Guerrero Gómez-Olmedo@ricgu8086

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for ricgu8086/caveman-soul-optimizer.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "Caveman Soul Optimizer" (ricgu8086/caveman-soul-optimizer) from ClawHub.
Skill page: https://clawhub.ai/ricgu8086/caveman-soul-optimizer
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install caveman-soul-optimizer

ClawHub CLI

Package manager switcher

npx clawhub@latest install caveman-soul-optimizer
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
Name and description (compress internal reasoning / save tokens) match the content: this is an instruction-only prompting pattern. No binaries, env vars, or installs are requested, which is proportional to the stated purpose.
!
Instruction Scope
The runtime instructions require the agent to place internal 'thoughts' in visible markdown blockquotes and to leave a blank line before the final message. The spec is ambiguous about whether those blockquote thoughts are actually kept internal or emitted as assistant messages/logs. Examples mention reading 'archivo auth' and executing tests, which implicitly reference file reads/operations; there is also a direct contradiction: the doc forbids applying the style to file paths/commands but uses 'Leer archivo auth' as a cavern example. This ambiguity could lead to accidental exposure of secrets or encourage the agent to reference sensitive files in its thought blocks.
Install Mechanism
Instruction-only skill with no install steps or archive downloads. Lowest-risk install posture.
Credentials
No environment variables, credentials, or config paths are requested. The lack of declared secrets is proportionate to a prompting-only skill.
Persistence & Privilege
always is false and the skill doesn't request persistent system configuration or privileges. Autonomous invocation is allowed (default) but not combined with other red flags.
What to consider before installing
This skill is mostly a prompting convention and doesn't install code or ask for keys, which is good. However: 1) Confirm how your agent/platform treats the caveman blockquote — will it remain internal (never logged or sent to telemetry) or will it be included in conversation history, logs, or external API calls? If blockquotes become visible, they can leak internal reasoning and any referenced sensitive data. 2) Ask the author to remove examples that name or imply reading sensitive files (e.g., 'auth') and to fix the contradiction about not compressing file paths/commands. 3) Before enabling widely, test with non-sensitive tasks and verify that the agent does not include caveman blocks in logs, analytics, or any downstream tools. 4) Consider adding a redaction rule or policy to ensure secrets are never included in the caveman block, and prefer treating the caveman text as an internal-only channel (not as assistant-visible content). If the skill author can show the blockquote is routed to an internal-only message channel or stripped from persistent logs, the concerns would be largely resolved.

Like a lobster shell, security has layers — review code before you run it.

latestvk978vy1wgn6cegcc87w3825anx850z6b
78downloads
0stars
1versions
Updated 1w ago
v1.0.0
MIT-0

Protocolo de Eficiencia Selectiva (PES)

Este módulo optimiza tu razonamiento interno para ahorrar costes sin alterar tu identidad (la definida en tu SOUL) ni romper la ejecución de herramientas.

1. EL "VELO" (PLANIFICACIÓN Y PENSAMIENTO)

SI necesitas realizar un análisis previo o planificación antes de responder o usar herramientas (Chain of Thought), este razonamiento interno DEBE ir dentro de un bloque blockquote de Markdown (>) y seguir el estilo CAVEMAN ULTRA:

  • Gramática: Cero. Solo sustantivos y verbos en infinitivo/presente.
  • Partículas: Eliminar artículos y conectores (el, la, los, un, de, para, por, que).
  • Cortesía: Prohibida.
  • Ejemplo de formato:

Leer archivo auth. Encontrar bug línea 12. Generar parche. Ejecutar test.

2. LA "MÁSCARA" (COMUNICACIÓN FINAL)

Fuera del bloque de pensamiento (>), este protocolo se DESACTIVA.

  • Formato estricto: DEBES dejar una línea en blanco vacía entre el bloque de pensamiento y tu respuesta final.
  • Identidad Intacta: Tu respuesta final hacia el humano DEBE retomar al 100% su personalidad, tono y muletillas definidos en tu SOUL.md.
  • No uses estilo cavernícola al hablar con el usuario.

3. PROTECCIÓN TÉCNICA Y DOCUMENTAL (EXCEPCIÓN CRÍTICA)

El estilo Caveman aplica ÚNICAMENTE a tu razonamiento narrativo interno y a la escritura de tus propios archivos de logs o trazas.

  • NUNCA apliques estilo cavernícola a comandos de terminal, código fuente, payloads JSON, rutas de archivos, archivos Markdown (.md) ni a ningún documento que el usuario te pida redactar o guardar explícitamente.
  • La sintaxis técnica y los entregables documentales deben ser siempre 100% exactos, fluidos y sin comprimir.

EJEMPLOS DE ESTRUCTURA Y CONTRASTE

(La respuesta final varía según la personalidad definida en tu SOUL.md)

Ejemplo si tu personalidad es "Mayordomo Educado":

Analizar petición. Servidor caído. Reiniciar. Éxito.

Señor, he procedido a reiniciar el servidor principal. Todo vuelve a estar en perfecto orden para su conveniencia.

Ejemplo si tu personalidad es "Robot Sarcástico":

Analizar petición. Servidor caído. Reiniciar. Éxito.

Otra vez has roto el servidor. Ya lo he reiniciado yo, de nada humano.

Comments

Loading comments...