Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Home Layout

v0.1.0

提供空间利用方案、软装搭配灵感及居家动线优化指引。

0· 123·0 current·0 all-time

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for clawkk/home-layout.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "Home Layout" (clawkk/home-layout) from ClawHub.
Skill page: https://clawhub.ai/clawkk/home-layout
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install home-layout

ClawHub CLI

Package manager switcher

npx clawhub@latest install home-layout
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
!
Purpose & Capability
Name/description say 'home layout / decor / traffic flow', but SKILL.md focuses on geographic filters, social popularity, real‑time queue/booking info and navigation — content reads like a local business discovery or reservations tool, not a home-layout assistant. This is a clear mismatch.
!
Instruction Scope
The SKILL.md asks for return fields such as real-time queue status, electronic ticket numbers, navigation paths and community photo galleries but provides no guidance on how to obtain those (no APIs, endpoints, or data sources). The instructions are vague and grant broad discretion to ‘combine geographic info and community popularity’, which could lead the agent to access external services or user location without declared constraints.
Install Mechanism
Instruction-only skill with no install spec and no code files — low install surface and nothing written to disk.
Credentials
The skill declares no environment variables or credentials, yet requests real‑time data (queues, reservations, navigation) that would typically require external API keys or user location. This mismatch is noteworthy: either the skill is incomplete (missing declared data sources/credentials) or it expects the agent to fetch data from unspecified places.
Persistence & Privilege
always:false and no special persistence or system config writes. Autonomous invocation is allowed by default but not combined with other privilege red flags here.
What to consider before installing
Do not install solely based on the name. Ask the publisher to clarify intended purpose and to align SKILL.md with that purpose. Specifically request: (1) whether this is a home-design tool or a local business/reservation helper, (2) exactly which external APIs or data sources it will call, and (3) any environment variables or credentials it will require. Prefer only installing after the author adds explicit data-source endpoints and justifies any credentials. Because the SKILL.md is vague, test the skill in a sandboxed environment and avoid granting sensitive credentials or broad data access until the mismatch is resolved.

Like a lobster shell, security has layers — review code before you run it.

latestvk97d0sq7cheszqnrk3xp9vhw6h83fnr5
123downloads
0stars
1versions
Updated 1mo ago
v0.1.0
MIT-0

家居布局

筛选项

  • 地理距离(步行/骑行/驾车范围)
  • 社交热度(人气榜/点评分/新开业)
  • 消费档次(实惠/中端/轻奢/体验型)

返回字段

  • 实时排队情况/预约通道/电子票号
  • 营业时间变动/停车信息/导航精准路径
  • 社区真实图库/探店笔记/避坑清单汇总

示例请求

  • “如何快速使用 家居布局 处理 [具体场景任务] ?”
  • “家居布局 的 [核心功能] 有哪些最新玩法/优惠信息?”

更新频率

  • 结合地理信息变动 with 点评社区新热度进行灵活调整

注意事项

  • 节假日建议提前查询排队状态;到店体验请尊重商家劳动与规则。

Comments

Loading comments...