Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
Columbia
v1.0.5提供哥伦比亚大学历史、学院设置、招生、学费资助、知名校友及学术实力等相关查询服务。
⭐ 0· 76·0 current·1 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Suspicious
medium confidencePurpose & Capability
Declared description (in Chinese) promises Columbia University–specific info (history, colleges, admissions, tuition, notable alumni, academic strength). SKILL.md instead frames 'columbia' as a brand/business overview (products/services, market distribution, competition). The mismatch suggests the skill may return company/brand information rather than university-focused content, or is ambiguous about which 'Columbia' it covers. No homepage or source is provided to disambiguate.
Instruction Scope
SKILL.md contains only high-level guidance for answering 'columbia' queries and does not instruct any file reads, network calls, or credential access. It is benign technically but vague: it gives the agent broad editorial discretion about which sections to include, which could produce incorrect or misleading answers if the intended subject (university vs company) is unclear.
Install Mechanism
Instruction-only skill with no install spec and no code files. This is the lowest install risk—nothing is written to disk or downloaded.
Credentials
No environment variables, credentials, or config paths are requested. The requested permissions are minimal and proportionate.
Persistence & Privilege
Default invocation settings (not always:true). The skill does not request elevated persistence or modify other skills/config; autonomous invocation is enabled by default but not combined with other concerning factors here.
What to consider before installing
This skill is low technical risk (no installs, no credentials), but its content is inconsistent: the public description promises Columbia University information while the instructions read like a company/brand profile. Before installing or enabling it, verify with the publisher which 'Columbia' the skill targets (University vs company/brand), ask for a homepage or sample responses, and prefer official sources for facts about admissions, tuition, or alumni. If you need university-specific information, do not rely on this skill until the SKILL.md is corrected to match the stated purpose.Like a lobster shell, security has layers — review code before you run it.
latestvk9725tr97ekcy9vsqcnzmn834n84wjeb
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
