Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Find Skills (yuanfa版)

v0.1.0

Helps users discover and install agent skills when they ask questions like "how do I do X", "find a skill for X", "is there a skill that can...", or express...

0· 177·0 current·0 all-time

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for yuanfa247/find-skills-yuanfa.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "Find Skills (yuanfa版)" (yuanfa247/find-skills-yuanfa) from ClawHub.
Skill page: https://clawhub.ai/yuanfa247/find-skills-yuanfa
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install find-skills-yuanfa

ClawHub CLI

Package manager switcher

npx clawhub@latest install find-skills-yuanfa
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
!
Purpose & Capability
The skill's name, description, and SKILL.md all align: it helps find and install other skills via the Skills CLI. However, registry metadata shown to you lists an owner ID (kn73n3gmx...) while the included _meta.json has a different ownerId (kn77ajmm...). The skill has no homepage and 'Source' is unknown, which reduces traceability. These metadata inconsistencies are unexplained and worth verifying with the publisher before trusting installs suggested by this skill.
!
Instruction Scope
SKILL.md stays on-topic (searching and installing skills) and does not ask the agent to read unrelated files or env vars. Concern: it advises using 'npx skills add <pkg> -g -y' which installs packages globally and skips confirmation prompts. Using npx to fetch and run packages executes third-party code on the user's machine — this advice encourages unattended, high-impact actions. The agent should not run global installs without explicit user consent and source verification.
Install Mechanism
This is an instruction-only skill (no install spec). That is low surface area for this skill itself. However, its recommended mechanism for obtaining other skills is 'npx skills add' which will fetch and execute code from package sources (GitHub/registries). That is expected for a package manager but carries the usual risks of executing remote packages; the SKILL.md does not provide guidance on vetting packages beyond linking to skills.sh.
Credentials
The skill requests no environment variables, no credentials, and no config paths. This is proportionate to the stated purpose of finding and suggesting installs.
Persistence & Privilege
always is false and the skill is user-invocable; that's normal. disable-model-invocation is false (agent could invoke autonomously), which is platform default. Combined with the instruction to run global, unattended installs, autonomous invocation would increase risk — ensure the agent is not allowed to run shell installs without explicit user approval.
What to consider before installing
This skill itself only helps find other skills and contains no code, so it's coherent with its description — but take precautions before following its install advice: 1) Verify the package/skill repository and publisher on skills.sh or GitHub before installing. Note the metadata mismatch between the registry owner ID and the included _meta.json ownerId — ask the publisher about that. 2) Avoid running 'npx ... -g -y' (global + unattended). Prefer interactive installs and omit '-y' so you can inspect prompts. 3) Treat any 'npx' install as executing remote code: review the repo, read install scripts, and prefer well-known authors. 4) If you need strong isolation, perform installs in a VM or container, or on a non-production account. 5) Require explicit confirmation from the user before performing any install, and do not allow autonomous agent runs of install commands.

Like a lobster shell, security has layers — review code before you run it.

latestvk97cf9sdknwa4jhn5jfzp3jhkh833yyb
177downloads
0stars
1versions
Updated 23h ago
v0.1.0
MIT-0

Find Skills

This skill helps you discover and install skills from the open agent skills ecosystem.

When to Use This Skill

Use this skill when the user:

  • Asks "how do I do X" where X might be a common task with an existing skill
  • Says "find a skill for X" or "is there a skill for X"
  • Asks "can you do X" where X is a specialized capability
  • Expresses interest in extending agent capabilities
  • Wants to search for tools, templates, or workflows
  • Mentions they wish they had help with a specific domain (design, testing, deployment, etc.)

What is the Skills CLI?

The Skills CLI (npx skills) is the package manager for the open agent skills ecosystem. Skills are modular packages that extend agent capabilities with specialized knowledge, workflows, and tools.

Key commands:

  • npx skills find [query] - Search for skills interactively or by keyword
  • npx skills add <package> - Install a skill from GitHub or other sources
  • npx skills check - Check for skill updates
  • npx skills update - Update all installed skills

Browse skills at: https://skills.sh/

How to Help Users Find Skills

Step 1: Understand What They Need

When a user asks for help with something, identify:

  1. The domain (e.g., React, testing, design, deployment)
  2. The specific task (e.g., writing tests, creating animations, reviewing PRs)
  3. Whether this is a common enough task that a skill likely exists

Step 2: Search for Skills

Run the find command with a relevant query:

npx skills find [query]

For example:

  • User asks "how do I make my React app faster?" → npx skills find react performance
  • User asks "can you help me with PR reviews?" → npx skills find pr review
  • User asks "I need to create a changelog" → npx skills find changelog

The command will return results like:

Install with npx skills add <owner/repo@skill>

vercel-labs/agent-skills@vercel-react-best-practices
└ https://skills.sh/vercel-labs/agent-skills/vercel-react-best-practices

Step 3: Present Options to the User

When you find relevant skills, present them to the user with:

  1. The skill name and what it does
  2. The install command they can run
  3. A link to learn more at skills.sh

Example response:

I found a skill that might help! The "vercel-react-best-practices" skill provides
React and Next.js performance optimization guidelines from Vercel Engineering.

To install it:
npx skills add vercel-labs/agent-skills@vercel-react-best-practices

Learn more: https://skills.sh/vercel-labs/agent-skills/vercel-react-best-practices

Step 4: Offer to Install

If the user wants to proceed, you can install the skill for them:

npx skills add <owner/repo@skill> -g -y

The -g flag installs globally (user-level) and -y skips confirmation prompts.

Common Skill Categories

When searching, consider these common categories:

CategoryExample Queries
Web Developmentreact, nextjs, typescript, css, tailwind
Testingtesting, jest, playwright, e2e
DevOpsdeploy, docker, kubernetes, ci-cd
Documentationdocs, readme, changelog, api-docs
Code Qualityreview, lint, refactor, best-practices
Designui, ux, design-system, accessibility
Productivityworkflow, automation, git

Tips for Effective Searches

  1. Use specific keywords: "react testing" is better than just "testing"
  2. Try alternative terms: If "deploy" doesn't work, try "deployment" or "ci-cd"
  3. Check popular sources: Many skills come from vercel-labs/agent-skills or ComposioHQ/awesome-claude-skills

When No Skills Are Found

If no relevant skills exist:

  1. Acknowledge that no existing skill was found
  2. Offer to help with the task directly using your general capabilities
  3. Suggest the user could create their own skill with npx skills init

Example:

I searched for skills related to "xyz" but didn't find any matches.
I can still help you with this task directly! Would you like me to proceed?

If this is something you do often, you could create your own skill:
npx skills init my-xyz-skill

Comments

Loading comments...