Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Emmestudio Brand

v1.0.0

Applica la brand identity EmmeStudio a qualsiasi output visivo o testuale. Usare quando si produce un documento, presentazione, preventivo, lettera, one-page...

0· 85·1 current·1 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
Name/description match the included files (brand guidelines, logo assets, templates references). However the SKILL.md tells the agent to 'download from Drive (emmestudio.team@gmail.com → CORTEX/BRAND/)' while the skill declares no credentials, env vars, or config paths for Drive access — this is an inconsistency (expected: instructions how to obtain access or declared required credential).
Instruction Scope
Runtime instructions stay within the branding domain (read guidelines, apply rules, use templates). The only out-of-scope element is the explicit instruction to fetch fonts/templates from a Google Drive account; that directs the agent toward an external endpoint/account not otherwise authorized in the skill metadata.
Install Mechanism
No install spec and no code files that execute — instruction-only skill with included static assets (SVGs, markdown). This is low-risk from an installation/execution perspective.
Credentials
The skill requests no environment variables or credentials, which is reasonable for an instruction-only branding helper — but it references a specific Google Drive account for resources without declaring any credential requirement. That mismatch could cause the agent to prompt the user for access or attempt to use account integrations unexpectedly.
Persistence & Privilege
The skill is not always-enabled and does not request persistent system privileges or modify other skills. Default autonomous invocation is allowed (platform default) and is not by itself flagged.
What to consider before installing
This skill appears to be a straightforward branding helper: it bundles brand guidelines and many SVG logos and instructs the agent how to produce 'on-brand' outputs. Two things to consider before installing: (1) the SKILL.md explicitly tells the agent to download fonts and templates from a Google Drive account (emmestudio.team@gmail.com → CORTEX/BRAND/) but the skill metadata does not declare any credentials or config for Drive access. That means the agent might (a) ask you to grant Drive access, (b) try to use a platform Google integration, or (c fail to obtain the templates — so be cautious about granting access and verify the Drive owner before sharing credentials. (2) The included assets are SVG files and markdown only — there is no executable code in the skill bundle, but SVGs can contain scripts in general; a quick manual inspection of the provided SVGs shows plain SVG path/style data (no obvious obfuscated scripts), which is expected for logos. Recommendations: review the included references/brand-system.md and the logo files to ensure they are the expected assets; if the agent requests Drive access, verify the account and prefer to upload required templates/fonts yourself rather than handing over persistent Drive credentials; confirm font licensing before distributing to third parties. If you want higher assurance, ask the publisher for clarity on how the Drive resources are expected to be accessed (e.g., public link vs. private account) — if the skill required programmatic access to your Google Drive (env vars / tokens) that would raise the concern level.

Like a lobster shell, security has layers — review code before you run it.

latestvk972ya1tt5gtw40f36rkgx4d4x83wc7t

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Comments