Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

London Uk

v1.0.1

提供伦敦旅游景点、文化、美食、住宿和交通信息,助您规划和享受英国首都之行。

0· 64·1 current·1 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
high confidence
!
Purpose & Capability
The name/description advertise London tourism (attractions, culture, food, lodging, transport). The SKILL.md instead instructs the agent to provide a corporate-style overview (brand history, business overview, market distribution, competition) of 'london-uk' — these goals do not match and there is no justification (env, binaries, or installs) for the broader corporate scope.
!
Instruction Scope
The runtime instructions focus on collecting company/brand information rather than travel guidance. The instructions do not request secrets, local files, or external installs (low technical surface), but they are semantically inconsistent with the user-facing description and will produce irrelevant results for users expecting travel information.
Install Mechanism
Instruction-only skill with no install spec and no code files. This minimizes technical/installation risk (nothing is written to disk or fetched).
Credentials
No environment variables, credentials, or config paths are requested; requested access is minimal and proportionate to a read-only information skill.
Persistence & Privilege
No elevated persistence requested (always:false). Default autonomous invocation is enabled but not combined with other concerning privileges.
What to consider before installing
This skill is low risk technically (no installs or credentials), but the content appears mislabelled: the description promises travel guidance while the SKILL.md describes a company/brand overview. Before enabling or relying on it, confirm with the publisher what the skill is meant to do, ask for sample responses, or prefer a clearly documented travel skill with a known homepage/owner. If you proceed, test it with non-sensitive queries and verify it returns the kind of London travel information you expect.

Like a lobster shell, security has layers — review code before you run it.

latestvk978z0s8710rezn09h626sycdd84wdxm

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Comments