Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Cobra Claw - Strike First. Strike Hard

v2.0.0

Your AI's dojo discipline — Kreese style. Strike First. Strike Hard. No Mercy. Read the markdown files and apply the doctrine. The model develops its own agg...

0· 1.6k·1 current·1 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Suspicious
View report →
OpenClawOpenClaw
Benign
high confidence
Purpose & Capability
Name/description describe a local dojo/personality CLI and practice 'katas'; the repository contains only local shell scripts and markdown that implement that functionality. No unrelated credentials, binaries, or services are required.
Instruction Scope
SKILL.md instructs only local CLI usage (./cobraclaw.sh ...) and katas. The included scripts only echo static text and invoke local kata scripts; they do not read arbitrary system files, reference external endpoints, or access environment variables beyond standard shell usage.
Install Mechanism
There is no install spec; this is instruction-only plus local scripts. Nothing is downloaded or extracted from remote URLs at runtime. README suggests a git clone URL but that is informational only.
Credentials
The skill declares no required environment variables, credentials, or config paths, and none of the scripts attempt to read secrets or external credentials.
Persistence & Privilege
The skill does not request always:true, does not modify other skills, and has no special persistence or privilege requests. It runs locally when invoked.
Assessment
This package is a small collection of local shell scripts that print doctrine text and run 'kata' scripts. It appears coherent and low-risk: no network calls, no secrets, no installs. Still, because these are executable scripts from an external source, review them before running on a sensitive host or run them in a sandbox/container. Note: test-skill.sh checks for executable bits on the kata files and may fail if permissions are not set; adjust permissions or inspect before executing.

Like a lobster shell, security has layers — review code before you run it.

cobra kaivk97cj6m4hp7x8s0paqnyr3shcd80dqkjemojivk97cj6m4hp7x8s0paqnyr3shcd80dqkjlatestvk9778f7180d0dwq3pgc5957p75815wwplatest - skill - personality - clivk9778f7180d0dwq3pgc5957p75815wwppersonalityvk97cj6m4hp7x8s0paqnyr3shcd80dqkj

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Comments