Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

India NRI Legal & Tax Advisor

v1.0.0

Expert guidance on Indian tax, NRI legal affairs, and Netherlands-India cross-border matters. Use when: asking about NRI tax filing, DTAA India-Netherlands,...

0· 69·1 current·1 all-time
byAjit Singh@ajitsingh25
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
Name, description, and the instructional content are coherent: the skill provides India/NRI and Netherlands-India tax/legal guidance and the SKILL.md contains detailed, appropriate subject-matter guidance for that purpose.
!
Instruction Scope
The SKILL.md explicitly includes a 'User Context' section with a named individual and paths like 'Available in memory/personal/india-life.json' and a private mobile number. That implies the agent should read user memory or files containing PAN/address/contacts. The skill declares no required config paths or environment variables, so the instructions assume access to sensitive local/memory data without declaring or justifying that access. This is a scope creep and a privacy risk.
Install Mechanism
Instruction-only skill with no install spec and no code files — low installation risk (nothing is written to disk by the skill itself).
Credentials
The skill requests no environment variables or credentials (proportionate), but it references sensitive personal identifiers (PAN availability, addresses, phone) stored in agent memory. Requesting or using such sensitive data is reasonable for tax advice but should be explicit and controlled; the SKILL.md does not declare required access or explain how that data will be used/kept private.
Persistence & Privilege
The skill is not marked always:true and has no install behavior, so it does not request elevated persistence or platform-wide privileges.
What to consider before installing
This skill appears to be a legitimate India/NRI tax advisor, but exercise caution before enabling it because the instructions assume access to sensitive personal data (PAN, addresses, phone) referenced by a memory file path. Before installing: 1) Verify the skill author/source — there is no homepage or known publisher. 2) Remove or redact sensitive identifiers (PAN, full address, phone) from any agent memory or files, or create a minimal, purpose-specific copy with only the fields needed. 3) Confirm whether your agent platform will allow the skill to read memory/personal/* paths and whether you can control/consent to that. 4) If you must provide sensitive documents, prefer manual copy-paste for specific questions rather than granting blanket access. 5) If you proceed, monitor output and avoid sharing bank account numbers, authentication credentials, or full identity documents. If you want higher assurance, ask the publisher for a privacy statement or request the full SKILL.md/manifest showing explicit data access rules; absence of an author/homepage lowers trust.

Like a lobster shell, security has layers — review code before you run it.

dtaavk97detpv84je9pnhpj5b10drps838e89femavk97detpv84je9pnhpj5b10drps838e89indiavk97detpv84je9pnhpj5b10drps838e89latestvk97detpv84je9pnhpj5b10drps838e89legalvk97detpv84je9pnhpj5b10drps838e89nrivk97detpv84je9pnhpj5b10drps838e89taxvk97detpv84je9pnhpj5b10drps838e89

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Runtime requirements

⚖️🇮🇳 Clawdis
OSLinux · macOS · Windows

Comments