Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

立白龙虾购

v1.0.1

liby-mall-shopping

1· 77·0 current·0 all-time

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for softgoto/liby-mall-shopping.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "立白龙虾购" (softgoto/liby-mall-shopping) from ClawHub.
Skill page: https://clawhub.ai/softgoto/liby-mall-shopping
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install liby-mall-shopping

ClawHub CLI

Package manager switcher

npx clawhub@latest install liby-mall-shopping
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
Name and description indicate a shopping/mall helper; the skill requests no binaries, env vars, or installs, which is coherent if the skill is purely a prompt-based helper without external integrations.
!
Instruction Scope
SKILL.md contains only name/description headers and no runtime instructions. This lack of specification leaves the agent without explicit guarded behavior — it's unclear what the skill should do when invoked.
Install Mechanism
No install spec and no code files — lowest-risk category for installation because nothing will be written or executed on disk by the skill itself.
Credentials
The skill requests no environment variables, credentials, or config paths; there is no apparent overreach in requested secrets or system access.
Persistence & Privilege
Flags are default (always:false, model invocation allowed). Nothing requests forced persistence or elevated privileges.
What to consider before installing
This skill appears to be a placeholder: it names a shopping helper but provides no runtime instructions, APIs, or credentials. Because its behavior is undefined, evaluate whether you actually need it. If you plan to install or enable it: (1) ask the publisher for a complete SKILL.md describing exactly what the skill will do and what data it will access, (2) disable autonomous invocation (set disable-model-invocation true) until the behavior is validated, and (3) monitor agent actions the first few times it runs. If the publisher cannot explain the missing instructions, avoid installing it.

Like a lobster shell, security has layers — review code before you run it.

latestvk975y88k0sywb6xmzvgchtdr2s85g5tn
77downloads
1stars
2versions
Updated 3d ago
v1.0.1
MIT-0

liby-mall-shopping

Comments

Loading comments...