Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Cambridge Uk

v1.0.5

提供剑桥大学历史、学院、申请条件、学费资助及校园生活等详细信息,助力英国留学了解与规划。

0· 69·1 current·1 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
high confidence
!
Purpose & Capability
Name/description say this is about Cambridge University admissions, fees, colleges and campus life, but SKILL.md content is generic (brand history, products, market distribution, competition) and reads like a corporate overview rather than university guidance — the requested behavior and stated purpose are inconsistent.
!
Instruction Scope
Instructions are vague and high-level: they do not specify sources, citation policy, or concrete runtime steps. They also frame use cases (product comparison, market analysis) that don't align with the advertised university information and grant broad discretion to the agent without boundaries.
Install Mechanism
No install spec and no code files — instruction-only skill; nothing will be written to disk or installed.
Credentials
No environment variables, credentials, or config paths requested; requested privileges are minimal and proportionate to an information-only skill.
Persistence & Privilege
Defaults used (not always, model invocation allowed). No indications the skill requests elevated persistence or modifies other skills/config.
What to consider before installing
This skill appears internally inconsistent: its description promises University of Cambridge admissions and campus guidance, but the SKILL.md gives a generic corporate-style outline and lacks sourcing or concrete runtime behavior. Because it is instruction-only and asks for no credentials, it is low technical risk, but you should: (1) ask the publisher for a homepage or authoritative data sources before trusting content; (2) request a revised SKILL.md that explicitly describes what the agent will fetch, how it will cite sources (official university pages), and what it will not do; (3) avoid entering any personal or account credentials into interactions with the skill; and (4) test the skill with non-sensitive queries to confirm it returns the expected university-focused information. If you need reliable admissions or financial-aid guidance, prefer skills that cite official Cambridge web pages or recognized education services.

Like a lobster shell, security has layers — review code before you run it.

latestvk9770ak82v0231e075g1j2h98h84xv9h

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Comments