Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Apify YouTube Email Scraper

v0.1.1

This skill should be used when the user asks to "find YouTube channel emails", "scrape YouTube contacts", "get YouTuber email addresses", "extract YouTube ch...

0· 0·0 current·0 all-time
byFuturize Rush@futurizerush
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
!
Purpose & Capability
The documented purpose (scraping YouTube channel emails via an Apify actor) aligns with the instructions, but the SKILL.md requires APIFY_API_TOKEN while the skill's registry metadata claims no required env vars/primary credential. That mismatch is incoherent: a legitimate Apify-based skill should declare the APIFY_API_TOKEN requirement in metadata.
Instruction Scope
SKILL.md stays on-topic: it instructs the agent to call Apify API endpoints to start an actor run, poll for completion, and fetch dataset items. It does not instruct the agent to read unrelated files or other environment variables. It does, however, collect personal contact data (emails) as its explicit purpose.
Install Mechanism
This is instruction-only with no install spec or code files, so nothing is written to disk or installed by the skill itself—low install risk.
!
Credentials
SKILL.md explicitly requires APIFY_API_TOKEN in environment, but the declared registry requirements show no env vars and no primary credential. Requiring an API token is reasonable for this purpose, but the omission in metadata is an incoherence that prevents informed consent and automated permission checks. Also the skill will access PII (email addresses), so token scope and handling matter.
Persistence & Privilege
The skill does not request persistent presence (always: false) and does not modify other skills or system settings. Autonomous invocation is allowed (the platform default) but not combined with any extra privileges in this package.
What to consider before installing
Do not install blindly. The SKILL.md requires APIFY_API_TOKEN but the skill metadata does not declare any required credentials—ask the publisher to fix the metadata. Before providing an Apify token, verify the referenced actor (futurizerush/youtube-email-scraper) on apify.com and review its source or behavior so you understand what data it collects and where results are stored. If you proceed, create a dedicated Apify API token with minimal scope, monitor its use, and be prepared to revoke it. Be aware the skill's purpose is harvesting contact emails (personal data); ensure this complies with platform ToS and applicable privacy laws. Because the skill's source/homepage is missing, treat its provenance as unknown and exercise extra caution.

Like a lobster shell, security has layers — review code before you run it.

ai-agentvk975yzkngdbzepkt6asspfxf0s84nvfaapifyvk975yzkngdbzepkt6asspfxf0s84nvfaemailvk975yzkngdbzepkt6asspfxf0s84nvfainfluencervk975yzkngdbzepkt6asspfxf0s84nvfalatestvk975yzkngdbzepkt6asspfxf0s84nvfalead-generationvk975yzkngdbzepkt6asspfxf0s84nvfamarketingvk975yzkngdbzepkt6asspfxf0s84nvfascrapingvk975yzkngdbzepkt6asspfxf0s84nvfayoutubevk975yzkngdbzepkt6asspfxf0s84nvfa

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Comments