Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Champions League

v1.0.5

提供欧洲冠军联赛球队、赛程、比分、球员与数据统计等权威信息查询服务。

0· 67·0 current·1 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
!
Purpose & Capability
Name/description claim real-time sports data (teams, schedules, scores, players, stats). SKILL.md instead instructs the agent to produce high-level 'background' and 'market/brand' analysis. This is a substantive mismatch: either the metadata is inaccurate or the instructions are incomplete.
!
Instruction Scope
SKILL.md is instruction-only and limited to producing background/history/market-style writeups. It does not reference fetching live scores, calling external sports APIs, or accessing any local files or credentials. The scope is narrow and safe, but does not match the advertised functionality.
Install Mechanism
No install spec and no code files (instruction-only). This minimizes risk from arbitrary downloads or disk writes.
Credentials
The skill requests no environment variables, credentials, or config paths — there are no disproportionate secret requests.
Persistence & Privilege
Defaults used (not always:true). The skill is user-invocable and may be called autonomously by the agent (platform default) but it does not request elevated persistence or modify other skills.
What to consider before installing
This skill's metadata promises live Champions League data (scores, schedules, players) but its SKILL.md only describes producing background/brand-style writeups. Before installing or enabling it, ask the publisher to clarify: (1) whether the skill provides live data and, if so, which APIs/endpoints it uses; (2) why the SKILL.md focuses on high-level background rather than match data; and (3) whether there are any hidden code files or network calls not shown. Test with sample queries in a safe environment: if the skill cannot fetch live scores or player stats as advertised, treat it as incomplete or mislabeled. Because it currently contains inconsistent information rather than explicit malicious behavior, proceed cautiously and prefer not to grant any credentials or broad access until the author provides a clear, matching SKILL.md or source.

Like a lobster shell, security has layers — review code before you run it.

latestvk974hreb5qjh9k9e6snc8wmja184wmyt

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Comments