Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Online Course Creator

v1.0.0

AI驱动的一键生成完整在线课程大纲、视频脚本、测验及营销材料,支持快速高效课程创作与推广。

1· 282·1 current·1 all-time

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for lvjunjie-byte/online-course-creator.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "Online Course Creator" (lvjunjie-byte/online-course-creator) from ClawHub.
Skill page: https://clawhub.ai/lvjunjie-byte/online-course-creator
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install online-course-creator

ClawHub CLI

Package manager switcher

npx clawhub@latest install online-course-creator
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
Name/description match the included code: index.js and example.js implement course outline, video script, quiz and marketing material generation. No unexpected binaries, services, or credentials are requested.
!
Instruction Scope
SKILL.md usage instructions are scoped to install and invoke the skill and include trigger phrases; however a pre-scan detected unicode-control-chars inside SKILL.md (prompt-injection pattern). The instructions do not ask for unrelated files/credentials, but hidden control characters can be used to manipulate downstream prompt processing — review raw SKILL.md bytes.
Install Mechanism
Registry lists no install spec (instruction-only), but the package includes package.json, index.js and example.js for Node.js usage. There are no external download URLs or extract steps in the files provided. This is low technical risk, but the mismatch (no install spec vs. included code) is worth being aware of.
Credentials
The skill requests no environment variables, no credentials, and code only uses local filesystem (fs, path). There are no obvious requests for unrelated secrets or external APIs in the provided files.
Persistence & Privilege
Flags show always:false and user-invocable:true. The skill does not request persistent elevated privileges or attempt to modify other skills or system-wide agent configuration in the provided code.
Scan Findings in Context
[unicode-control-chars] unexpected: Hidden/unicode control characters were detected in SKILL.md. These are not necessary for the described course-generation functionality and are commonly used in prompt-injection attempts to alter how text is parsed or executed. The rest of the code appears local-only (no network calls), but you should inspect the raw SKILL.md (hex/byte view) and remove or validate any control characters before using.
What to consider before installing
What to do before installing: - Inspect SKILL.md in a raw/hex editor for hidden unicode control characters and remove them. The scanner flagged this as a prompt-injection signal. - Review index.js and example.js locally (they appear to only use fs/path and generate content) and run them in an isolated sandbox or container first. - Verify the package origin (the skill lists a GitHub URL and OpenClaw Team author; confirm the repository and commits match the published package). Do not run 'clawhub install' or any install commands on a production machine until you've validated locally. - Run a quick static check for network calls (search for http, https, fetch, axios, net, child_process.exec) — the provided files show none, but confirm no hidden dynamic requires are present. - If you accept the risk, run the code in a disposable environment (container/VM) and inspect outbound network traffic during execution. If you are not comfortable with these steps, do not install.

Like a lobster shell, security has layers — review code before you run it.

latestvk97fhmc71mq0dqnwa4ewjs0fyh836d36
282downloads
1stars
1versions
Updated 20h ago
v1.0.0
MIT-0

Online-Course-Creator

AI 驱动的课程创作技能 - 一键生成完整在线课程材料

功能

  • 📚 课程大纲生成 - 根据主题自动生成结构化课程大纲
  • 🎬 视频脚本写作 - 为每个课程单元撰写详细的视频脚本
  • 📝 测验和作业生成 - 创建配套的测验题目和实践活动
  • 📢 营销材料创建 - 生成课程描述、宣传文案、邮件模板

使用场景

当用户需要:

  • 创建在线课程但不知道如何组织内容
  • 快速生成课程教学材料
  • 为已有内容设计课程结构
  • 制作课程营销和推广材料

触发词创建课程课程大纲视频脚本课程设计online coursecourse creatorteaching materials

定价

$119/月 - 专业课程创作工具

预期收益

  • 目标用户:在线教育从业者、知识博主、企业培训师
  • 市场规模:全球在线教育市场 $3500 亿+
  • 预期收益:$6,000-15,000/月

命令

# 安装
clawhub install online-course-creator

# 使用示例
创建一门关于"Python 数据分析"的课程,包含 8 个模块
为"机器学习入门"课程生成视频脚本
为我的课程创建测验题目
生成课程营销邮件模板

作者

OpenClaw Team

版本

1.0.0

Comments

Loading comments...