Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Apify Google News Scraper

v0.1.1

This skill should be used when the user asks to "scrape Google News", "get news articles", "search for news", "extract news data", "monitor news topics", "ge...

0· 0·0 current·0 all-time
byFuturize Rush@futurizerush
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
Capability signals
Crypto
These labels describe what authority the skill may exercise. They are separate from suspicious or malicious moderation verdicts.
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
The name/description (Apify Google News Scraper) matches the runtime instructions: the SKILL.md instructs calling the Apify actor futurizerush/google-news-scraper and fetching dataset items from api.apify.com. That functionality is coherent with the stated purpose. However, the registry metadata lists no required environment variables or primary credential while the SKILL.md explicitly requires APIFY_API_TOKEN — this mismatch is unexpected.
Instruction Scope
The instructions are focused: they show how to start an Apify actor run, poll for completion, and fetch dataset items from https://api.apify.com. They only reference an API token (APIFY_API_TOKEN) and standard network calls; they do not ask the agent to read unrelated files, system paths, or other credentials. No unexpected external endpoints are used beyond Apify.
Install Mechanism
This is an instruction-only skill with no install spec and no code files, so nothing is written to disk or downloaded by the skill itself. That is the lowest-risk install mechanism.
!
Credentials
The SKILL.md requires APIFY_API_TOKEN (sensitive credential) for API access, but the registry metadata declares no required env vars or primary credential. The token request is legitimate for Apify usage, but the metadata omission is misleading and could cause automated reviewers or users to miss that a secret is needed. The skill should declare APIFY_API_TOKEN as a required credential/primaryEnv.
Persistence & Privilege
The skill does not request persistent/always-on inclusion and does not modify other skills or agent-wide configs. Autonomous invocation is allowed (platform default) but is not combined with other high-privilege requests here.
What to consider before installing
Before installing or enabling this skill: (1) note that SKILL.md requires an APIFY API token but the registry metadata does not list it — treat that as a metadata bug and assume you'll need to provide APIFY_API_TOKEN. (2) Only provide an APIFY token if you trust the actor/owner; verify the actor name (futurizerush/google-news-scraper) on Apify and ideally use a token scoped to a dedicated/minimal Apify account. (3) Ask the skill publisher to update registry metadata to declare APIFY_API_TOKEN as a required credential so automated tooling and reviewers can see the dependency. (4) If you have doubts about the owner (source unknown, no homepage), avoid supplying your main Apify credentials and consider running the actor manually in a sandboxed account to inspect outputs first.

Like a lobster shell, security has layers — review code before you run it.

ai-agentvk97dnh8xqhgs1wbcb1kzzbn5ex84nm0nai-automationvk97dnh8xqhgs1wbcb1kzzbn5ex84nm0napifyvk97dnh8xqhgs1wbcb1kzzbn5ex84nm0ngoogle-newsvk97dnh8xqhgs1wbcb1kzzbn5ex84nm0nlatestvk97dnh8xqhgs1wbcb1kzzbn5ex84nm0nmonitoringvk97dnh8xqhgs1wbcb1kzzbn5ex84nm0nnewsvk97dnh8xqhgs1wbcb1kzzbn5ex84nm0nscrapingvk97dnh8xqhgs1wbcb1kzzbn5ex84nm0n

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Comments