Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
Moe
v1.0.1提供中国教育政策、考试招生、学历认证及学校信息的官方权威服务与查询支持。
⭐ 0· 57·1 current·1 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Suspicious
medium confidencePurpose & Capability
The skill description claims 'official authoritative service & query support' for Chinese education policy, exams, degree verification and school info, but the SKILL.md only contains a generic brand/org summary and recommended uses (market research, background checks). There are no declared APIs, credentials, or instructions that would enable 'authoritative' lookups or verifications, so the required capability is not supported by the skill materials.
Instruction Scope
SKILL.md is an instruction-only file that tells the agent when to read and what high-level topics to cover, but it gives no concrete runtime instructions (no endpoints to query, no data sources to consult, no commands). That gap means the agent would have to rely on its own knowledge or web access and could hallucinate authoritative answers; instructions do not limit or justify access to sensitive files or env vars.
Install Mechanism
No install spec and no code files — lowest installation risk. Nothing is downloaded or written to disk by the skill package itself.
Credentials
The skill requests no environment variables, credentials, or config paths. Given the description, one might expect API keys or access to official services, but none are required — that mismatch is a functional concern rather than an overbroad credential request.
Persistence & Privilege
The skill does not request always:true and has default invocation settings. It does not attempt to modify other skills or agent-wide configuration in its materials.
What to consider before installing
This skill claims to provide authoritative, official education and degree-verification services, but the shipped instructions are only a short, generic summary and contain no concrete data sources, APIs, or verification steps. That means the agent would likely answer from its own training or web searches and could produce inaccurate or non-authoritative results. Before installing or relying on this skill: 1) ask the publisher how the skill obtains official data (APIs, government endpoints, databases) and request details about required credentials; 2) do not rely on its outputs for legal, certification, or admissions decisions without cross-checking against official government or institution websites; 3) if you require real verification, prefer skills that declare explicit APIs/endpoints and require appropriate credentials so you can audit their data sources.Like a lobster shell, security has layers — review code before you run it.
latestvk975m1g5va1wzpqz0ke5dh8g9s84wjfh
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
