Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
Linkedin Humanizer
v1.0.0Aggressively rewrites LinkedIn text to remove AI indicators and add human traits, ensuring posts and comments read authentically before publishing.
⭐ 0· 31·0 current·0 all-time
bySergey Bulaev@sergebulaev
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Suspicious
medium confidencePurpose & Capability
The name/description match the SKILL.md and the provided regex/rules. It is an instruction-only text-rewrite skill that uses regex replacements, sentence restructuring, and required 'human fingerprints' — all coherent with 'humanizer' functionality. No unrelated binaries, env vars, or install steps are requested.
Instruction Scope
Overall the instructions stay inside rewriting scope (regex scrubbing, structural edits, and asking the user when data is missing). However there are notable contradictions and risky behaviors: the doc mandates 'Never introduce facts that weren't in the input' and 'Don't fabricate' yet the example output adds a concrete number and named entity not present in the input (35k, LinkedIn) — this inconsistency raises the risk the agent might fabricate despite the rule. Also the 'ADD' pass requires adding a named entity and a specific number per 100 words; if the user doesn't provide them the instructions say to ask, but the requirement itself could pressure adding facts that change perceived truthfulness. The SKILL.md also promises a 'per-sentence perplexity estimate' but gives no algorithm or safe guardrails for how that metric is computed or whether it requires external model calls.
Install Mechanism
No install spec and no code files beyond instruction and reference docs. Instruction-only skills have low install risk because nothing is written to disk or downloaded automatically.
Credentials
The skill requests no environment variables, no credentials, and no config paths. There is no request for unrelated secrets or system access.
Persistence & Privilege
The skill is not marked always:true and is user-invocable only; it does not request to modify other skills or system settings and has no install-time persistence.
What to consider before installing
This skill is coherent with its stated task (rewriting LinkedIn text to hide AI patterns) but has two issues you should consider before installing:
- Contradictory rules about fabrication: The doc explicitly forbids inventing facts and says to ask the user for missing numbers/anecdotes, but the example shows fabricated facts. Ask the author to confirm and to enforce a human-in-the-loop: require explicit user consent before inserting any numbers, names, dates, or other facts. Prefer a default behavior of refusing to add facts without user-provided values.
- Potential for deceptive use: The tool is designed to evade AI detectors. That makes it useful for legitimate editing, but also for deceptive publishing or policy violations. Consider whether using such a tool could violate LinkedIn's terms, company policy, or your own ethical boundaries.
Practical steps before use:
- Request clarification from the skill author about the apparent example fabrication and ask them to update SKILL.md so the behavior is unambiguous (e.g., require interactive prompts for any missing specifics).
- Test thoroughly with non-sensitive drafts and confirm the skill never injects new factual claims without explicit user approval. Verify the diff output is clear and shown to the user before finalizing.
- Prefer workflows that keep a human review step and log changes. If you need to comply with workplace rules, do not use this skill to alter truth claims or publish content that could mislead others.
Given these contradictions and the potential for misuse, treat the skill with caution and get the author to remove the ambiguity around fabrication and required 'human fingerprints' before enabling it broadly.Like a lobster shell, security has layers — review code before you run it.
latestvk970e5q4mmfef1z0nzb577ky4h84vbxvlinkedinvk970e5q4mmfef1z0nzb577ky4h84vbxvmarketingvk970e5q4mmfef1z0nzb577ky4h84vbxvsocial-mediavk970e5q4mmfef1z0nzb577ky4h84vbxv
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
