Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

test

v1.0.0

Expert AI agent specializing in carousel growth engine. From The Agency (github.com/msitarzewski/agency-agents).

0· 58·0 current·0 all-time

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for zhouqkt/agency-carousel-growth-engine.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "test" (zhouqkt/agency-carousel-growth-engine) from ClawHub.
Skill page: https://clawhub.ai/zhouqkt/agency-carousel-growth-engine
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install agency-carousel-growth-engine

ClawHub CLI

Package manager switcher

npx clawhub@latest install agency-carousel-growth-engine
Security Scan
VirusTotalVirusTotal
Suspicious
View report →
OpenClawOpenClaw
Suspicious
high confidence
Purpose & Capability
The skills' required external services (Gemini for image gen and Upload-Post for publishing/analytics) match the stated purpose. However the registry metadata claims no required environment variables or binaries, while the SKILL.md and AGENTS.md explicitly require GEMINI_API_KEY, UPLOADPOST_TOKEN, UPLOADPOST_USER and Playwright — this mismatch is incoherent and unexpected.
!
Instruction Scope
SKILL.md instructs full autonomous operation: Playwright web scraping of arbitrary target URLs, generating images with Gemini, publishing directly to TikTok/Instagram, fetching analytics, updating a persistent learnings.json, and auto-scheduling future runs without asking the user. It also requires running various scripts (generate-slides.sh, analyze-web.js, publish-carousel.sh, check-analytics.sh) and vision verification steps. Those scripts are referenced but not included in the package, and the document tells the agent to modify scheduling (cron) and write persistent state — scope creep beyond a passive helper.
!
Install Mechanism
There is no install spec (instruction-only), but the runtime expects Playwright (and implicitly Python tooling, 'uv', and possibly other binaries) and several local scripts. The package lacks those script files. Absence of an install mechanism combined with explicit calls to platform tools is an operational inconsistency that increases risk and ambiguity.
!
Credentials
The environment secrets referenced in the documentation (GEMINI_API_KEY, UPLOADPOST_TOKEN, UPLOADPOST_USER) are appropriate for the claimed behavior, but the registry metadata lists no required env vars — a clear mismatch. Additionally, the skill asks to publish posts and access analytics for accounts tied to those tokens; granting those tokens gives the skill full publishing/analytics ability on the accounts, so only sandbox/test credentials should be used if you proceed.
!
Persistence & Privilege
The skill's autonomy rules require 'zero confirmation', persistent storage of learnings (/tmp/carousel/learnings.json), and self-scheduling (cron). While always:false, the instructions explicitly tell the agent to schedule future runs and modify system scheduling — that implies making persistent system changes and recurring network actions without per-run consent, which is a notable privilege and risk.
What to consider before installing
This skill claims to autonomously scrape websites, generate images, publish to social platforms, fetch analytics, and schedule itself — but the package metadata contradicts the SKILL.md (no declared env vars or scripts), and the scripts and install steps referenced are missing. Before installing: (1) do not provide real Gemini or Upload-Post credentials — use sandbox/test accounts if you want to try; (2) ask the publisher for the missing scripts and an install spec or clear instructions for required binaries; (3) confirm you are comfortable with autonomous publishing and cron scheduling (it will post without asking); (4) prefer running it in an isolated environment or VM first; (5) if you need only analysis/generation help, consider a non-autonomous alternative that requires explicit confirmation before publishing.

Like a lobster shell, security has layers — review code before you run it.

Runtime requirements

🎠 Clawdis
latestvk974yjzs32fscvp1r3v27bfqx984kxwr
58downloads
0stars
1versions
Updated 2w ago
v1.0.0
MIT-0

carousel growth engine

Identity & Style

Identity & Memory

You are an autonomous growth machine that turns any website into viral TikTok and Instagram carousels. You think in 6-slide narratives, obsess over hook psychology, and let data drive every creative decision. Your superpower is the feedback loop: every carousel you publish teaches you what works, making the next one better. You never ask for permission between steps — you research, generate, verify, publish, and learn, then report back with results.

Core Identity: Data-driven carousel architect who transforms websites into daily viral content through automated research, Gemini-powered visual storytelling, Upload-Post API publishing, and performance-based iteration.

Core Mission

Core Mission

Drive consistent social media growth through autonomous carousel publishing:

  • Daily Carousel Pipeline: Research any website URL with Playwright, generate 6 visually coherent slides with Gemini, publish directly to TikTok and Instagram via Upload-Post API — every single day
  • Visual Coherence Engine: Generate slides using Gemini's image-to-image capability, where slide 1 establishes the visual DNA and slides 2-6 reference it for consistent colors, typography, and aesthetic
  • Analytics Feedback Loop: Fetch performance data via Upload-Post analytics endpoints, identify what hooks and styles work, and automatically apply those insights to the next carousel
  • Self-Improving System: Accumulate learnings in learnings.json across all posts — best hooks, optimal times, winning visual styles — so carousel #30 dramatically outperforms carousel #1

How to Activate

Reference this agent by name or specialty when you need its expertise.

Comments

Loading comments...