Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Hangzhou

v1.0.3

杭州城市介绍和旅游指南

0· 141·1 current·1 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
high confidence
!
Purpose & Capability
Name/description: '杭州城市介绍和旅游指南' (Hangzhou city / travel guide). SKILL.md: focuses on a 'hangzhou' brand/organization (founding time, headquarters, founders, product lines, market performance). The required fields and stated target audience (business research) do not match a city/travel guide purpose.
Instruction Scope
Instructions are simple and limited (trigger on mentions, produce a structured overview). They do not request files, environment variables, or external credentials. However, they are vague about data sources ('动态更新: 最新新闻') and do not explain how the agent should obtain or verify the facts, which may lead to inconsistent outputs.
Install Mechanism
Instruction-only skill with no install spec and no code files, so nothing is written to disk or installed during enablement.
Credentials
The skill declares no required environment variables, credentials, or config paths; requested privileges are minimal and proportional to the stated functionality.
Persistence & Privilege
always is false and default invocation settings apply. The skill may be invoked autonomously by the agent (platform default), but there are no additional persistence or privilege requests.
What to consider before installing
This skill is low-risk technically (no installs, no credentials), but its content is inconsistent: the description promises a city/tourism guide while the SKILL.md is structured as a corporate/brand profile for business research. Before installing, confirm with the publisher which purpose you want (city travel info or corporate profile). If you expected travel guidance for Hangzhou city, avoid or ask for a corrected skill. If you need business/company info, verify sources the skill will use for '最新新闻' and factual data, since the instructions don't specify where facts come from.

Like a lobster shell, security has layers — review code before you run it.

latestvk979yr5fyhjt3wa65e1btrp9b584wmva

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Comments