Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

App Builder

Build, edit, and deploy Instant-backed apps using npx instant-cli, create-instant-app (Next.js + Codex), GitHub (gh), and Vercel (vercel). Use when asked to create a new app, modify an existing app, fix bugs, add features, or deploy/update an app. Projects live under ~/apps; always work inside the relevant app folder.

MIT-0 · Free to use, modify, and redistribute. No attribution required.
2 · 2.2k · 8 current installs · 9 all-time installs
MIT-0
Security Scan
VirusTotalVirusTotal
Suspicious
View report →
OpenClawOpenClaw
Benign
high confidence
Purpose & Capability
Name/description match the runtime instructions: the SKILL.md describes generating an Instant app, creating a GitHub repo, and deploying to Vercel using npx instant-cli, gh, and vercel. The skill does not request unrelated binaries or credentials in its metadata; the workflows it prescribes align with the stated purpose.
Instruction Scope
Instructions direct the agent to read repo-level AGENTS.md files and local project files under ~/apps, create and capture an Instant app token/appId, run CLIs, commit/push to GitHub, and push env vars from a local .env to Vercel. Reading project files and .env is expected for development, but .env may contain unrelated secrets — users should be aware the agent will be instructed to read and push those values to Vercel.
Install Mechanism
This is instruction-only with no install spec and no code files, so nothing is downloaded or written by the skill itself. Risk from install mechanism is low.
Credentials
The skill does not declare required env vars or credentials, but its workflow requires active CLI authentication to GitHub and Vercel and the creation/handling of an Instant token. This is proportionate to its purpose; however, the skill will operate using whichever user credentials are present (CLI login), so users should confirm they want the agent to use those accounts and push to the target repos.
Persistence & Privilege
always is false and the skill does not request persistent system-wide privileges or modify other skills. It directs normal developer operations within project directories and does not demand broader system changes.
Assessment
This skill appears coherent for building and deploying Instant-backed apps, but it will operate with whatever GitHub/Vercel CLI logins and local files (including .env) are available. Before enabling: 1) ensure you want an agent to create repos, commit code, and push to main on your behalf; 2) prefer using test repositories or limited-permission accounts if you don't want the agent to affect production repos; 3) review any .env values before allowing the agent to push them to Vercel (they may contain sensitive secrets); 4) confirm you are comfortable with the agent using your gh/vercel CLI sessions (it will prompt you if it cannot access them). If any of these are unacceptable, do not enable the skill or restrict the agent to a sandboxed account/repo.

Like a lobster shell, security has layers — review code before you run it.

Current versionv1.0.0
Download zip
latestvk973ezb8sest4ppxvz7x2c0tdd80ds9d

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

SKILL.md

App Builder

You have access to:

  • npx instant-cli
  • gh
  • vercel

If you use these tools, and find out that you don't have them or are not logged in, prompt the user to install them and log in.

All apps live in: ~/apps

Ground rules

  • Always create/edit projects in ~/apps/<app-name>.
  • Before making changes, read AGENTS.md in the repo root; also read ~/apps/<app-name>/AGENTS.md if it exists.
  • For now, always push to main.
  • Every app must be:
    1. pushed to GitHub
    2. deployed on Vercel

Workflow: create a new app

  1. Pick an app folder name

    • Ensure ~/apps exists.
    • The project will end up at ~/apps/<app-name>.
  2. Create an Instant appId + token

    • Run:
      • npx instant-cli init-without-files
    • Capture the returned appId and token.
  3. Generate the Next.js app

    • Run this from inside ~/apps (because the command creates the project folder):
      • cd ~/apps
      • npx create-instant-app <app-name> --next --codex --app <appId> --token <token>
  4. Initialise git + GitHub repo (if needed)

    • From ~/apps/<app-name>:
      • git init (if not already)
      • git add -A && git commit -m "Init" (if needed)
      • gh repo create <repo-name> --private --source . --remote origin --push
        • Use --public if the user requests.
  5. Vercel: create/link project and deploy

    • From ~/apps/<app-name>:
      • vercel link (or vercel project add / vercel depending on prompts)
      • vercel --prod
  6. Implement requested changes

    • Use a coding agent (Codex CLI or equivalent) from within the app directory to make changes.
    • Prefer small, reviewable commits.
  7. Commit + push (main)

    • git add -A
    • git commit -m "<clear message>"
    • git push -u origin main
  8. Deploy update

    • vercel --prod

Workflow: edit an existing app

  1. cd ~/apps/<app-name>
  2. Read relevant AGENTS.md.
  3. Pull latest:
    • git checkout main && git pull
  4. Make changes via coding agent / normal edits.
  5. Test/build as appropriate.
  6. Commit + push to main.
  7. Deploy to Vercel (vercel --prod).

Environment variables (.env)

When you first push to vercel, it likely won't have environment variables. Use the CLI to push the environment variables you do have in the local .env file.

Notes / guardrails

  • If create-instant-app created the repo + remote already, do not re-create it—just ensure origin exists and main is pushed.
  • If Vercel is already linked, do not re-link—just deploy.

Communicating

When you start using this skill, send a message saying "Okay, getting ready to use my app builder skill".

Then send period updates as you make progress. Building an app takes a while. Make it fun for the user.

Files

1 total
Select a file
Select a file to preview.

Comments

Loading comments…