Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Awesome Design MD

v1.0.0

收录50+知名网站的设计系统DESIGN.md文件,支持一键查看和复制,助力AI复刻顶级网站视觉风格。

1· 228·2 current·2 all-time
bylaojun@laojun509
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
Capability signals
CryptoCan make purchases
These labels describe what authority the skill may exercise. They are separate from suspicious or malicious moderation verdicts.
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
high confidence
!
Purpose & Capability
The SKILL.md and README both state the repo includes 50+ DESIGN.md files and preview assets, and runtime instructions assume files at ~/.openclaw/workspace/skills/awesome-design-md/design-md/<site>/DESIGN.md. The manifest shows only per-site README.md placeholders that point to external URLs (getdesign.md), and there are no DESIGN.md or preview.html files listed. This is a clear mismatch: the skill promises local design system files but doesn't include them.
!
Instruction Scope
Runtime instructions are limited to listing, reading (cat) and copying (cp) files under the skill's workspace path — that scope is appropriate for a local file collection. However, because the expected DESIGN.md files are missing, following the instructions will fail. Also note the cp instruction will write into the user's project root and could overwrite files if run without inspection; users/agents should inspect file contents before copying.
Install Mechanism
This is an instruction-only skill with no install spec and no code to be written to disk at install time, which is low risk from an install mechanism perspective.
Credentials
The skill requests no environment variables, credentials, or config paths — consistent with a read-only design-document collection.
Persistence & Privilege
Default flags are used (always: false, model invocation allowed). The skill does not request persistent presence or elevated privileges and does not modify other skills or global config.
What to consider before installing
Do not assume the repo contains the DESIGN.md files advertised. Before using: (1) Inspect the skill folder (~/.openclaw/workspace/skills/awesome-design-md/design-md/) to confirm the actual files present. The manifest shows only README placeholders linking to getdesign.md rather than DESIGN.md and preview assets — so cat/cp commands in SKILL.md will likely fail. (2) If files are missing but you need them, visit the referenced external site (getdesign.md) or contact the maintainer to obtain the real DESIGN.md files. (3) Review licensing and copyright for any third‑party design systems before copying into your project. (4) Never run cp or automated copy commands without first previewing the content to avoid accidental overwrites. The skill is internally inconsistent (claims bundled files but provides placeholders), so treat it as untrusted until the actual DESIGN.md contents and licensing are verified.

Like a lobster shell, security has layers — review code before you run it.

latestvk97f4bmvw1s1re3z6evjrkyk1h84h935

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Comments