Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

nexus-corporate-onboarder

v2.1.1

Design and automate corporate employee onboarding programs with AI. Create adaptive learning paths by role, compliance training modules, microlearning sequen...

0· 109·0 current·0 all-time

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for shuwanito/nexus-corporate-onboarder.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "nexus-corporate-onboarder" (shuwanito/nexus-corporate-onboarder) from ClawHub.
Skill page: https://clawhub.ai/shuwanito/nexus-corporate-onboarder
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install nexus-corporate-onboarder

ClawHub CLI

Package manager switcher

npx clawhub@latest install nexus-corporate-onboarder
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
!
Purpose & Capability
The skill advertises integrations with enterprise HRIS platforms (SAP, Workday, BambooHR) and analytics on training and completion data. Those capabilities normally require service credentials, API tokens, or explicit configuration paths, but the skill declares no required environment variables, no config paths, and no installation steps. This mismatch suggests the declared capabilities are not reflected in what the skill actually requests, which is incoherent.
!
Instruction Scope
The SKILL.md workflow instructs the agent to 'audit existing onboarding', 'analyze training completion rates and engagement metrics', and to integrate with HRIS systems. It also includes allowed-tools: web-search, web-fetch, filesystem — giving the agent the ability to read local files and make network requests. However, there are no constraints or specifics on which files/data to access, how to authenticate, or where results are sent. The instructions are open-ended and grant broad discretion to collect and transmit potentially sensitive internal HR data.
Install Mechanism
No install spec and no code files (instruction-only). That limits the risk of arbitrary code being written to disk or executed during install. Instruction-only skills reduce install-time surface.
!
Credentials
No environment variables, credentials, or config paths are declared despite the skill's need to access HRIS data in practice. That absence is suspicious: either the skill expects interactive/manual credential exchange (not documented) or it intends to access local data via filesystem/web without declaring required scopes. The allowed 'filesystem' tool effectively grants local data access without any declared justification or boundary.
Persistence & Privilege
always is false and there are no indications the skill requests permanent or elevated platform privileges or modifies other skills. Autonomous invocation is allowed (platform default) but does not by itself raise a red flag here.
What to consider before installing
This skill is internally inconsistent: it claims to integrate with enterprise HR systems and to read/analyze onboarding data, yet it doesn't declare how it will authenticate or which files it will access. Before installing or enabling it, ask the vendor for: (1) a clear data flow diagram showing what data is read, where it's stored, and where it's sent; (2) exact auth mechanisms and required scopes (OAuth flows, API keys) and whether credentials are ever stored; (3) a list of filesystem paths the agent will access and justification for each; (4) an option to run in a sandboxed environment or on isolated infrastructure; and (5) source code or an audit / privacy whitepaper if handling sensitive HR data. Do not supply corporate credentials or place sensitive HR data in locations accessible to the agent until these questions are answered. If you must test, do so with dummy data in an isolated test environment and monitor network and filesystem activity.

Like a lobster shell, security has layers — review code before you run it.

latestvk977gbjpwasfk73avpvhted2k5854fhr
109downloads
0stars
2versions
Updated 1w ago
v2.1.1
MIT-0

Corporate Onboarder

AI-powered corporate training and onboarding automation for enterprises.

Capabilities

  • Design adaptive onboarding paths customized by role, department, and seniority
  • Create compliance training modules with continuous assessment
  • Build microlearning sequences with spaced repetition
  • Generate training ROI dashboards per department
  • Integrate with HRIS systems (SAP, Workday, BambooHR)
  • Automate internal certification programs
  • Analyze training completion rates and engagement metrics

Workflow

  1. Audit existing onboarding and training processes
  2. Map competency frameworks by role and department
  3. Design adaptive learning paths with branching logic
  4. Create compliance modules aligned to industry regulations
  5. Build assessment rubrics with automated grading
  6. Configure ROI tracking dashboards for L&D leadership
  7. Generate improvement proposals based on completion and engagement data

Guidelines

  • All training content must meet WCAG 2.2 AA accessibility standards
  • Compliance modules require legal team review before deployment
  • Training paths must include both knowledge checks and practical exercises
  • ROI calculations must use conservative estimates with clear methodology
  • Content must be available in mobile-first format for field employees

Want this agent working for YOUR business?

We build custom AI agents tailored to your specific needs. This skill is just a preview of what's possible.

  • 7-day free trial — no commitment, no credit card
  • From 50 EUR/month — cancel anytime
  • Your data stays yours — runs on your infrastructure

Get started: nexusaicorp@gmail.com | Calculate your ROI

Built by NEXUS AI Corp — 75 specialized AI agents, 23 departments, infinite possibilities.

Comments

Loading comments...