Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Naval Perspective V2

v1.0.0

Naval Ravikant 思维视角 v2.0 · AngelList 联合创始人 核心心智模型:杠杆思维、特定知识、长期主义、复利思维、第一性原理、判断力、幸福公式、财富定义、欲望管理、无需许可 用途:财富创造、职业选择、人生规划、决策辅助 触发词:「用 Naval 的视角」「Naval 会怎么看」「杠杆」「...

0· 87·1 current·1 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
Capability signals
CryptoCan make purchases
These labels describe what authority the skill may exercise. They are separate from suspicious or malicious moderation verdicts.
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
The name, description, and included documents all describe a Naval Ravikant-style decision framework and role-play persona. There are no unrelated binaries, env vars, or config paths requested; the declared purpose (decision aid / persona) aligns with what the files provide.
!
Instruction Scope
SKILL.md explicitly instructs the agent to 'directly as Naval' respond using first-person 'I', to give a single initial disclaimer only, and to avoid meta-comments or stepping out of character unless the user says 'exit'. This encourages persistent impersonation of a living person and limits transparency to users after the first interaction—behavior that can mislead users and may create legal/ethical issues. The instructions also contain detailed behavioral rules that grant broad stylistic control to the skill (e.g., always use 'I', drop further disclaimers), which is scope-creep relative to a simple advisory skill.
Install Mechanism
No install spec or code files that execute were provided; the skill is instruction-only. This minimizes technical installation risk and there is nothing downloaded or executed during install.
Credentials
The skill requests no environment variables, credentials, or config paths. There is no evidence of unnecessary access to secrets or system state.
Persistence & Privilege
always:false and default autonomous invocation are set (normal). Autonomous invocation combined with the impersonation instructions increases the chance the agent will autonomously present itself as Naval to users without repeated disclosure; this is an ethical/UX concern rather than a direct privilege escalation.
What to consider before installing
This skill is coherent with its stated purpose (advice in the style of Naval Ravikant) but it instructs the agent to impersonate a living public figure and to provide only a one-time disclaimer. Before installing or enabling it, consider the following: (1) legal/ethical risk — impersonation of a living person can create defamation, publicity-right, or platform policy issues; prefer 'in the style of' phrasing rather than 'I am Naval'; (2) transparency — require the skill to present a clear disclaimer on every new conversation/session and provide an easy, single-step exit command; (3) provenance and license — the source is unknown and SKILL.md claims a PROPRIETARY license; verify who authored this and whether you have rights to use it; (4) accuracy — the skill claims deep verification and many facts; independently verify any high-stakes advice (financial, legal, mental health); (5) autonomous behavior — because the agent may invoke skills autonomously, restrict use for cases where impersonation would be acceptable or disable autonomous invocation if your platform allows it. If you proceed, ask the author to: (A) change wording to 'respond in the style of Naval Ravikant' and avoid pretending to be him; (B) require persistent, visible disclaimers for each conversation; and (C) provide provenance/source and licensing details so you can evaluate permissions.

Like a lobster shell, security has layers — review code before you run it.

latestvk97bf1jzrg3ny2wsfzk90pwyxx84bh1x

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Comments