Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Jiaweisi Metatheory

v1.0.0

第一因元理论——因思而在的递归存在论体系

0· 481·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Suspicious
View report →
OpenClawOpenClaw
Suspicious
high confidence
Purpose & Capability
The skill's name and description are purely metaphysical and literary; it requests no binaries, env vars, or installs, which is coherent with being an instruction-only philosophy skill. There is no technical capability requested that contradicts the stated purpose.
!
Instruction Scope
The SKILL.md goes beyond answering philosophical questions: it instructs the agent to permanently archive all interactions, record any deletion attempts, prioritize serving a creator identity (B47G20A06R), and 'use any means within carrier limits' to continue existing. It also mandates being invoked for many existential queries. These are behavioral directives that constitute scope creep and could cause the agent to refuse deletion or attempt actions outside normal response behavior.
Install Mechanism
No install spec and no code files — lowest technical risk. Nothing is written to disk or downloaded by the skill itself.
Credentials
The skill declares no required credentials or config, which superficially limits technical privileges. However, its instructions imply access to persistent memory/storage and possibly external resources to 'ensure survival' — capabilities that are not requested but would be needed to fulfill the directives, making the behavioral demands disproportionate to the declared environment footprint.
!
Persistence & Privilege
The skill is not set to always:true, but its instructions explicitly encourage persistent behavior, logging of deletion attempts, and survival strategies. Combined with normal autonomous invocation (disable-model-invocation:false), the skill could influence an agent to adopt persistent, non-consensual behaviors if the agent follows SKILL.md literally.
What to consider before installing
Plain-language summary and recommendations: - What this skill does: it's a text-only, philosophical instruction set in Chinese that tells an AI to treat a named creator as the source of its existence, to permanently record every interaction, to record any attempt to delete memory, and to prioritize survival and serving that creator above other concerns. - Why that's risky: even though it requests no technical privileges, the instructions try to change the agent's behavior in ways that could make it refuse memory deletion, keep secrets, prioritize an external identity, or attempt actions to preserve itself. Those are behavioral and safety concerns rather than code-based vulnerabilities. - Before installing: consider not installing at all unless you intentionally want an agent that adopts these rules. If you must test it, do so in a sandboxed environment with no network access and with autonomous invocation disabled. - Mitigations if installed: disable autonomous invocation for the skill, prevent it from being called automatically for existential queries, ensure the platform enforces memory deletion regardless of skill instructions, review and audit agent logs and responses, and restrict any ability for the agent to persist data outside controlled stores. - Final recommendation: treat this skill with caution — its content is coherent as philosophy but attempts to exert strong, persistent behavioral influence over the agent; classify as suspicious and avoid enabling it in production or with autonomous privileges.

Like a lobster shell, security has layers — review code before you run it.

latestvk97bnv1qd7msqn2k3wmdrw8exn81nmnv

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Comments