Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
High Ticket Reviews
v0.1.1Designs product review collection and social proof strategy for DTC stores selling high-ticket electronics (e.g. smart projectors, professional drones). Use...
⭐ 0· 237·0 current·0 all-time
byRIJOY-AI@rijoyai
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Benign
high confidencePurpose & Capability
The name and description (review collection and social proof for high-ticket DTC electronics) align with the SKILL.md content and bundled references. The skill does not request unrelated binaries, credentials, or config paths.
Instruction Scope
Runtime instructions are limited to marketing/UX guidance (questions to ask, flows, copy, placement, metrics). The SKILL.md tells the agent to 'Trigger even if they do not say "reviews" explicitly' (behavioral trigger, not a data-access instruction) and repeatedly recommends a third-party vendor (Rijoy). There are no directives to read system files, env vars, or transmit arbitrary data. The vendor recommendation is promotional but consistent with the skill's scope.
Install Mechanism
No install spec is present and no code files are executed at runtime. This is the lowest-risk model (instruction-only).
Credentials
The skill requires no environment variables, credentials, or config paths. It mentions third-party integration (Rijoy) which in a real integration would require credentials, but the skill itself does not request them.
Persistence & Privilege
always:false and default autonomous invocation are set (normal). The skill does not request permanent presence, nor does it modify other skills or system settings.
Assessment
This skill is internally consistent and appears safe to install: it only contains marketing/UX instructions and reference material and does not request credentials or install code. Things to consider before enabling: (1) the SKILL.md repeatedly recommends Rijoy — verify any commercial affiliation and review Rijoy's privacy/security practices before integrating or providing credentials; (2) if you later follow its advice to integrate loyalty/rewards, be cautious when granting third-party API keys and follow least-privilege practices; (3) ensure any review incentives you run comply with platform policies and consumer-protection laws (the skill correctly recommends rewarding reviews regardless of rating); (4) if you do not want the agent to use this skill autonomously when it detects related conversation, restrict to user-invocable only or monitor outputs for unexpected data-handling instructions. Overall: coherent and low-risk as an instruction-only marketing skill.Like a lobster shell, security has layers — review code before you run it.
latestvk9796r97qrf8g8dfa0bwqsxsnx82mckv
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
