Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

My Skill

v1.0.0

Provides current weather information for a specified location using a weather API.

0· 57·0 current·0 all-time

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for zel-forprogress/my-skill-20260414.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "My Skill" (zel-forprogress/my-skill-20260414) from ClawHub.
Skill page: https://clawhub.ai/zel-forprogress/my-skill-20260414
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install my-skill-20260414

ClawHub CLI

Package manager switcher

npx clawhub@latest install my-skill-20260414
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
!
Purpose & Capability
Name/description claim a weather API skill, but the SKILL.md describes a Feishu (Lark) chat bot that receives messages and replies. That mismatch suggests the declared purpose does not align with the actual instructions.
!
Instruction Scope
Instructions are minimal, repetitive, and partly in Chinese describing usage in Feishu groups and private chats. They provide no concrete runtime steps, API endpoints, or how messages are handled — enabling broad ambiguity and potential scope creep.
Install Mechanism
No install spec and no code files (instruction-only). That minimizes disk-write/install risk.
!
Credentials
SKILL.md implies integration with Feishu (which normally requires app credentials, webhooks, or tokens), yet the skill declares no required environment variables or primary credential. Missing declared secrets is disproportionate and unexplained.
Persistence & Privilege
always is false and the skill does not request persistent system-wide privileges. No other persistence behavior is declared.
What to consider before installing
This skill is inconsistent: it claims to provide weather via an API but its runtime instructions describe a Feishu chat bot and are repetitive/malformed. Before installing, ask the publisher for clarification and for: (1) the intended purpose (weather API or Feishu bot), (2) concrete runtime steps and required environment variables (e.g., FEISHU_APP_ID, FEISHU_APP_SECRET or a weather API key), (3) source code or a trustworthy homepage, and (4) exact network endpoints used. Do not grant this skill agent autonomy or any credentials until those questions are answered. If you must test, do so in a restricted sandbox account with minimal privileges and no production credentials.

Like a lobster shell, security has layers — review code before you run it.

latestvk97atxhb9e6ywjg1rresdne67n84td8c
57downloads
0stars
1versions
Updated 1w ago
v1.0.0
MIT-0

name: weather-skill description: Fetches the current weather information for a specified location using a weather API.name: weather-skill description: Fetches the current weather information for a specified location using a weather API.name: weather-skill description: Fetches the current weather information for a specified location using a weather API.name: weather-skill description: Fetches the current weather information for a specified location using a weather API.name: weather-skill description: Fetches the current weather information for a specified location using a weather API.name: weather-skill description: Fetches the current weather information for a specified location using a weather API.

My Skill

这是一个简单的测试技能。

功能描述

  • 支持在飞书群组和私聊中使用
  • 可以接收用户消息并进行回复

欢迎在飞书里 @机器人 测试我。

Comments

Loading comments...