Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Bill Gates

v0.1.4

Information assistant for Bill Gates 比尔盖茨. Get biography, latest news, career highlights, and social media updates.

0· 97·0 current·1 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Pending
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
The skill is named 'Bill Gates' (a person) and the registry description promises biography, latest news, and social media updates, but the SKILL.md describes 'bill-gates' as a brand/organization and only lists high-level company-style details. This mismatch between name/intent and instructions is inconsistent but not obviously malicious.
Instruction Scope
SKILL.md is minimal and self-contained: it instructs the agent to provide background (founding, core business, market, trends) when asked. It does not ask the agent to read unrelated files, access credentials, or exfiltrate data. It also does not prescribe contacting third-party endpoints or using credentials.
Install Mechanism
No install spec or code files are present (instruction-only), so nothing will be written to disk or installed by the skill itself.
Credentials
The skill requests no environment variables, binaries, or config paths — its declared needs are proportionate to providing an information assistant.
Persistence & Privilege
always is false and the skill is user-invocable. It does not request permanent presence or elevated privileges.
What to consider before installing
This skill is lightweight and doesn't ask for credentials or install anything, but two things to consider before installing: (1) the name/description suggest a person (Bill Gates) while the SKILL.md talks about a brand/organization — ask the publisher which entity the skill targets if that matters to you; (2) the description mentions 'latest news' and 'social media updates' but the instructions do not specify how live updates should be fetched — verify whether the skill will use a trusted news/social API or rely on the agent's web access. Also note the source/homepage is unknown; if you need authoritative or up-to-date information, prefer skills with clear sources and documented data feeds.

Like a lobster shell, security has layers — review code before you run it.

latestvk97egp0g5x500rhzqzet1dmc8d84xcd8

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Comments