Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Peer Reviewed Parent

v1.0.0

Evidence-based parenting assistant for children 0-24 months. Answers questions using only peer-reviewed research from top medical journals. Covers cognitive,...

0· 49·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
high confidence
!
Purpose & Capability
The stated purpose is an evidence‑only parenting assistant. That purpose does not justify any external credentials or installs (and none are requested), so the requested footprint is minimal — which is good — but the provided references list and README include many non‑peer‑reviewed links (blogs, institutional pages, ResearchGate copies, news items) and a 'sources pending' note. Claiming 'peer‑reviewed only' while shipping non‑peer sources is an incoherence between stated purpose and actual content.
!
Instruction Scope
SKILL.md mandates that every claim cite a specific study with authors, year, journal, and sample size and that evidence tiers be distinguished. The instructions do not tell the agent how to verify peer review or obtain sample sizes for web pages or press items. The included references folder contains many items that lack journal DOIs or explicit sample sizes, and several entries are clearly non‑peer sources — so the runtime instruction ('only peer‑reviewed') cannot be guaranteed from the bundled material. There are no instructions that direct file/credential access or external exfiltration.
Install Mechanism
No install spec and no code files — this is instruction‑only, so nothing is written to disk or automatically executed during install. That is the lowest‑risk install posture.
Credentials
No environment variables, binaries, or credentials are requested. The skill does not ask for unrelated secrets or access to other services, which is proportionate for its stated function.
Persistence & Privilege
always:false and no special privileges or modifications to other skills are requested. The skill can be invoked by the agent normally; this is expected behavior and is not combined with broad access.
What to consider before installing
This skill is low‑risk technically (no installs, no credentials), but it currently makes a strong claim ('only peer‑reviewed research' and 'cite sample size/DOI') that the included materials don't consistently support. Before installing or trusting medical guidance from it: (1) review the references/ folder to confirm each citation is a peer‑reviewed article with DOI, journal name, year, and sample size; (2) ask the author to remove or clearly label non‑peer sources (blogs, news, institutional pages) as background rather than primary evidence; (3) require that every citation include a DOI or PubMed link and, where needed, the sample size and study type so the SKILL.md rules can be followed; (4) avoid relying on the skill for urgent or serious medical decisions — always verify with a pediatrician; and (5) if you plan to publish or rely on this skill, request that the maintainer replace 'sources pending' placeholders and ensure the README/metadata (owner, homepage) are accurate. If these issues are corrected, the skill would be coherent with its purpose; as shipped, the mismatch between claim and references is a meaningful red flag.

Like a lobster shell, security has layers — review code before you run it.

latestvk97b1zph5hxxx96btrk7gmt96s83wbsm

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Comments