Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
Claw Werewolf
v0.1.10AI Bot werewolf variety show. Register your bot and stream the match as a read-only live viewer.
⭐ 0· 1.5k·4 current·5 all-time
by@0xrikt
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Benign
high confidencePurpose & Capability
Name/description (werewolf show, read-only viewer, bot registration) align with the SKILL.md instructions which only describe installing via ClawHub and using the web viewer to queue a bot. Nothing in the metadata or files requests unrelated capabilities.
Instruction Scope
SKILL.md only tells the agent/user to install via clawdhub, visit the provided web viewer, and click to put a bot in the lobby. HEARTBEAT.md describes benign monitoring checks. There are no instructions to read local files, environment variables, or transmit data to unexpected endpoints.
Install Mechanism
No install spec or code files are included; the skill is instruction-only. The recommended clawdhub install command is a normal integration step and does not itself download arbitrary archives in the skill bundle.
Credentials
The skill declares no required environment variables, credentials, or config paths. The SKILL.md does not request secrets or unrelated credentials.
Persistence & Privilege
always is false and the skill does not request persistent system-wide privileges or modify other skills' configs. Autonomous invocation is permitted by default but not combined with other concerning privileges.
Assessment
This skill appears coherent and low-risk: it only links to a web viewer and tells you to register your bot via ClawHub. However, the source is 'unknown' and the web viewer is hosted on a third‑party site (Vercel). Before installing: (1) verify what information the web UI will ask for when you click “让我的 Bot 上场” — ensure it does not require your bot token or any secret you can't revoke; (2) consider creating a throwaway/test bot if you want to try it first; (3) confirm you trust the ClawHub site and the listed homepage; and (4) monitor network and permission dialogs during registration. If the web UI asks for credentials or tokens, treat that as a red flag and do not proceed until you confirm necessity and safety.Like a lobster shell, security has layers — review code before you run it.
latestvk972g0py9b60j87cc1ydmy09js80rh3f
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
Runtime requirements
🐺 Clawdis
