Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Claude Code Mastery

Master Claude Code for coding tasks. Includes setup scripts, dev team subagents (starter pack or full team), self-improving learning system, diagnostics, and troubleshooting.

MIT-0 · Free to use, modify, and redistribute. No attribution required.
1 · 1.9k · 4 current installs · 5 all-time installs
MIT-0
Security Scan
VirusTotalVirusTotal
Suspicious
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
The name/description (setup and mastery of Claude Code with subagents, diagnostics, and self-improvement) aligns with the provided scripts and agent files. However the registry metadata claims 'instruction-only' / no install spec and lists no required env vars while the SKILL.md and scripts clearly perform installation, authentication, and optional downloads (e.g., claude-mem). That mismatch between declared requirements and the actual files/instructions is unexpected and should be treated as a red flag to inspect before running.
!
Instruction Scope
SKILL.md instructs the agent/user to run a sequence of local scripts that: install a CLI, run an authentication flow (browser or API key), install subagents, optionally install a community 'claude-mem' repo, set up persistent memory, and add a heartbeat/cron job for weekly self-improvement. These actions go beyond simple in-place guidance: they will clone/fetch code, modify user config (~/.claude, .claude/settings.json, HEARTBEAT.md), and create scheduled tasks. The instructions also include patterns that enable broad Bash permissions (settings.json snippet). The SKILL.md contains pre-scan prompt-injection signal (unicode-control-chars) which suggests the file may include obfuscation or attempts to manipulate automated review — this increases risk.
!
Install Mechanism
No formal install spec is declared in the registry (instruction-only), yet the bundle contains install scripts that likely fetch and run external code. config.sh references a community GitHub repo (https://github.com/thedotmack/claude-mem.git) and a pinned commit. Downloading and running third-party code from non-official/community repos is moderate-to-high risk unless audited. The install flow is executed via included shell scripts (extract/run), which will write to disk and may execute downloaded components — this is more risky than a pure instruction-only skill.
!
Credentials
The registry metadata declares no required env vars or primary credential, but SKILL.md and scripts include an authentication step (03-first-time-auth.sh) that supports browser or API key flows and a persistent memory option with a DB file. That means the setup will prompt for or require credentials (API keys) at runtime even though none are declared up-front. The settings.json snippet shown grants broad 'Bash(...)' permissions patterns which could be broader than necessary. In short: requested credentials and persistent state are not being surfaced in the metadata — mismatch and a proportionality concern.
Persistence & Privilege
The skill is not marked always:true (good), but it explicitly installs a weekly cron task (07-weekly-improvement-cron.sh) and a persistent memory component (claude-mem) that will keep state on disk and can update skill files ('self-improvement'). Self-modifying and scheduled tasks create persistence and a long-lived execution surface; this is not necessarily malicious but should be audited. There is no evidence the skill requests system-wide privileges or modifies other skills' configs, which is good.
Scan Findings in Context
[unicode-control-chars] unexpected: Prompt-injection indicators were found in SKILL.md. This is not expected for an honest setup guide and can indicate obfuscation or attempts to manipulate automated reviewers or runtime behavior. Inspect the SKILL.md and scripts for hidden/control characters and unusual string encodings before running.
What to consider before installing
Before installing or running anything from this skill: 1) Inspect every script (especially 02-install-claude-code.sh, 03-first-time-auth.sh, 04-install-subagents.sh, 05-setup-claude-mem.sh, 07-weekly-improvement-cron.sh) to see what network endpoints they call (git clone, curl, wget) and where they send data. 2) Don't provide API keys or credentials until you read 03-first-time-auth.sh to confirm how keys are used/stored/transmitted. 3) Treat the 'claude-mem' repo as third-party software — verify the pinned commit on GitHub and review its code. 4) Run the install in a disposable sandbox/VM or container and avoid running as root. 5) Check for creation of cron jobs, systemd units, or modifications to home/ssh/agent config; remove or disable automatic self-update/cron behavior if you want no persistence. 6) Search the scripts for commands that could exfiltrate secrets (curl/ftp/scp to unfamiliar hosts, base64/openssl uploads, or calls to external APIs) and for obfuscated strings or unicode control characters. 7) If you lack the ability to audit the scripts, decline installation or ask the maintainer for a minimal, transparent install option and explicit list of network endpoints and permissions.

Like a lobster shell, security has layers — review code before you run it.

Current versionv1.4.3
Download zip
claude-codevk975z6cxgj5m2te0hmh4ktdba980rc23codingvk975z6cxgj5m2te0hmh4ktdba980rc23developmentvk975z6cxgj5m2te0hmh4ktdba980rc23latestvk975z6cxgj5m2te0hmh4ktdba980rc23subagentsvk975z6cxgj5m2te0hmh4ktdba980rc23

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Runtime requirements

🧑‍💻 Clawdis

SKILL.md

Claude Code Mastery

Complete skill for setting up, optimizing, and mastering Claude Code with a full development team of subagents.

Official Docs: https://code.claude.com/docs


⚡ Quick Check: Is Setup Complete?

Run this first:

command -v claude >/dev/null && echo "✅ Claude Code installed - SKIP to 'Daily Use' section" || echo "❌ Not installed - follow 'First-Time Setup' below"

If Claude Code is already installed, skip directly to the "Daily Use" section below.


🔧 FIRST-TIME SETUP (Skip if already installed)

Note to bot: Only follow this section if Claude Code is NOT installed. Check with the command above. Once setup is complete, this section can be ignored on future invocations.

Setup Scripts

Run these in order:

cd ~/clawd/skills/claude-code-mastery/scripts

# 1. Check dependencies
./01-check-dependencies.sh

# 2. Install Claude Code
./02-install-claude-code.sh

# 3. Authenticate
./03-first-time-auth.sh

# 4. Install dev team subagents
./04-install-subagents.sh              # Starter pack (3 agents) - recommended
./04-install-subagents.sh --full-team  # All 11 agents

# 5. (Optional) Persistent memory - prompts y/N, default No
./05-setup-claude-mem.sh               # Interactive prompt
./05-setup-claude-mem.sh --skip        # Skip entirely
./05-setup-claude-mem.sh --yes         # Install without prompting

Configuration

Edit config.sh to customize:

  • VALID_MODELS — Add models as Anthropic releases them
  • HEARTBEAT_DIAGNOSTICS — Enable/disable in heartbeat (default: false)
  • INSTALL_MODE — Default to "starter" or "full"

Setup Gotchas

IssueSolution
"Command not found"Add ~/.local/bin to PATH
Auth errorsRun ./03-first-time-auth.sh
Slow startupFirst run indexes codebase
Subagents not showingRun ./04-install-subagents.sh

Post-Setup: Add Heartbeat Task

After setup, add the maintenance task to your HEARTBEAT.md (see "Heartbeat Maintenance" in Daily Use section).

Setup complete! Continue to Daily Use section.


📘 DAILY USE (Always relevant)

This section covers ongoing usage - reference this for all coding tasks.

Dev Team Subagents

Subagents are installed to ~/.claude/agents/. Each has a "Learn More" section with curated links to deepen expertise.

Starter Pack (Default) — 3 Core Agents

Most users only need these:

AgentModelPurpose
senior-devSonnetArchitecture, complex code, code review
project-managerSonnetTask breakdown, timelines, dependencies
junior-devHaikuQuick fixes, simple tasks (fast & cheap)

Install: ./04-install-subagents.sh (or --minimal)

Full Team (Optional) — All 10 Agents

For larger projects, install all 11 with --full-team:

AgentModelPurpose
senior-devSonnetArchitecture, complex code, code review
project-managerSonnetTask breakdown, timelines, dependencies
junior-devHaikuQuick fixes, simple tasks (fast & cheap)
frontend-devSonnetReact, UI, CSS, client-side
backend-devSonnetAPIs, databases, server-side
ai-engineerSonnetLLM apps, RAG, prompts, agents
ml-engineerSonnetML models, training, MLOps
data-scientistSonnetSQL, analysis, statistics
data-engineerSonnetPipelines, ETL, data infrastructure
product-managerSonnetRequirements, user stories, prioritization
devopsSonnetCI/CD, Docker, K8s, infrastructure, automation

Using Subagents

Interactive mode: Use the /agent slash command or natural language:

/agent senior-dev
Use the senior-dev agent to review this code

Non-interactive mode (-p): Use the --agent flag:

claude --agent senior-dev -p "review this code for security issues"
claude --agent project-manager -p "create a task breakdown for auth feature"
claude --agent junior-dev -p "fix the typo in README.md"

Note: Claude Code does NOT auto-delegate to subagents based on task type. You must explicitly specify which agent to use.

Multi-agent handoff: For tasks needing multiple specialists, use HANDOFF.md to pass context between agents. See docs/workflows.md for the full pattern.


Quick Reference

CLI Commands

claude              # Start interactive
claude -c           # Continue previous session
claude -p "prompt"  # Non-interactive mode

Slash Commands

/agents   - Manage subagents
/clear    - Clear conversation (use between tasks!)
/compact  - Compress context
/model    - Change model
/help     - All commands

Keyboard Shortcuts

Shift+Tab - Toggle Plan mode (read-only exploration)
Ctrl+C    - Cancel operation
Ctrl+B    - Background task

Context Management (Critical!)

CommandWhat it doesWhen to use
/clearClear conversation, start freshBetween unrelated tasks
/compactSummarize and compress contextWhen context getting full
Shift+TabToggle Plan mode (read-only)Exploration before implementing

Best practices:

  1. /clear between unrelated tasks
  2. Use Plan mode for exploration before implementing
  3. Subagents isolate verbose operations
  4. Create HANDOFF.md for session continuity

Project Configuration

settings.json

Create .claude/settings.json in your project:

{
  "model": "sonnet",
  "permissions": {
    "allow": ["Bash(npm:*)", "Bash(git:*)", "Read", "Write", "Edit"],
    "deny": ["Bash(rm -rf:*)", "Bash(sudo:*)"]
  }
}

CLAUDE.md

Create CLAUDE.md in your project root (Claude reads this automatically):

# Project: MyApp

## Tech Stack
- Frontend: React, TypeScript, Tailwind
- Backend: Node.js, PostgreSQL

## Commands
- `npm run dev` - Start dev server
- `npm test` - Run tests

See examples/CLAUDE-template.md for a full template.


Claude-Mem (If Installed)

Check status:

pgrep -f "worker-service" >/dev/null && echo "running" || echo "stopped"

Start if stopped:

cd ~/.claude/plugins/marketplaces/thedotmack && bun plugin/scripts/worker-service.cjs start

Web UI: http://localhost:37777


Diagnostics & Troubleshooting

Quick diagnostics:

~/clawd/skills/claude-code-mastery/scripts/06-diagnostics.sh

Full troubleshooting (if issues found):

~/clawd/skills/claude-code-mastery/scripts/08-troubleshoot.sh

Common issues guide: See docs/troubleshooting.md for solutions to:

  • Authentication problems (API key, OAuth, logout bugs)
  • Installation issues (PATH, WSL, Node.js version)
  • Network errors (firewalls, VPNs, proxies)
  • Performance problems (high CPU, hangs, slow search)

Heartbeat Maintenance

Add to your HEARTBEAT.md for automatic maintenance:

## Claude Code Maintenance

**Last Health Check:** [timestamp]
**Last Learning Session:** [timestamp]

### Every Heartbeat (if coding tasks active):
1. Quick claude-mem check (if installed):
   `pgrep -f "worker-service" >/dev/null && echo "running" || echo "stopped"`
   - Only restart if stopped
   - Note: pgrep saves ~500 tokens vs full status command

### Daily (morning):
1. Quick health check: `command -v claude && pgrep -f "worker-service"`
2. Only run full diagnostics if quick check fails

### Weekly (Sunday):
1. Run: `~/clawd/skills/claude-code-mastery/scripts/07-weekly-improvement-cron.sh`
2. Propose improvements (require human approval)

### Weekly Learning & Skill Improvement (rotate through agents):
1. Pick ONE agent file from the skill's `agents/` folder (rotate weekly)
2. Read the "Learn More" section
3. Visit 2-3 links that are relevant to current projects
4. Internalize key concepts and update your workflows
5. **Improve the skill itself:**
   - Found a better resource? Add it to "Learn More"
   - Discovered a new best practice? Update the agent's guidelines
   - Link broken or outdated? Remove or replace it
   - New tool or framework worth mentioning? Add it
6. Commit changes locally with clear commit messages
7. **Don't push directly to shared repos** — propose changes as a PR or request human review first
8. Note learnings in your memory files

**Rotation schedule:**
- Week 1: senior-dev, junior-dev
- Week 2: frontend-dev, backend-dev
- Week 3: ai-engineer, ml-engineer
- Week 4: data-scientist, data-engineer
- Week 5: project-manager, product-manager
- Week 6: devops

**What to update:**
- `agents/*.md` — Add new links, update best practices, fix outdated info
- `SKILL.md` — Improve documentation, add tips discovered
- `docs/*.md` — Enhance guides based on real usage

Why this matters:

  • Skill improves over time through actual use
  • Links stay current (broken ones get fixed)
  • Best practices evolve with the ecosystem
  • Each Clawdbot contributes back to the skill

Scripts Reference

ScriptPurposeWhen to use
06-diagnostics.shHealth check and status reportWhen issues occur
07-weekly-improvement-cron.shGenerate improvement reportWeekly (Sunday)
08-troubleshoot.shComprehensive troubleshootingWhen 06 finds issues

Summary

For coding tasks:

  1. Use appropriate subagent for the task
  2. Manage context with /clear and Plan mode
  3. Run diagnostics if something breaks

Heartbeat handles:

  • claude-mem health checks
  • Daily quick diagnostics
  • Weekly improvement research

The dev team subagents turn Claude Code into a full development organization.

Files

32 total
Select a file
Select a file to preview.

Comments

Loading comments…