Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

OpenClaw Course Reference

v1.0.0

Comprehensive reference to install, configure, deploy, secure, optimize, and extend OpenClaw agents with local AI, VPS setup, and skill development guidance.

1· 192·0 current·0 all-time

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for chatgptkrylor/openclaw-course.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "OpenClaw Course Reference" (chatgptkrylor/openclaw-course) from ClawHub.
Skill page: https://clawhub.ai/chatgptkrylor/openclaw-course
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install openclaw-course

ClawHub CLI

Package manager switcher

npx clawhub@latest install openclaw-course
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
The name/description (OpenClaw course reference) matches the delivered assets: a SKILL.md, seven large reference markdown modules, and a local index.js searcher. The code and docs are consistent with a documentation/search skill.
!
Instruction Scope
The SKILL.md and referenced modules contain actionable install and runtime instructions that go beyond passive documentation: examples include piping remote install scripts (curl | bash / iwr | iex), running privileged Docker (--privileged and mounting /var/run/docker.sock), copying binaries into /usr/local/bin with sudo, and patterns for agents to read/write/edit arbitrary files and run elevated exec commands. Those are expected for a course teaching deployment, but they expand the skill's operational scope and could be dangerous if followed without review.
Install Mechanism
The skill itself has no install spec (instruction-only + local index.js), which is low risk. However, the course documentation recommends installing software by downloading remote install scripts (e.g., https://openclaw.ai/install.sh, https://ollama.com/install.sh) and pulling docker images; those example commands invoke third-party endpoints and would execute arbitrary code on the host if run directly.
Credentials
The skill declares no required env vars or credentials — appropriate for a reference. The docs, however, show many example env vars and API keys (OPENAI_API_KEY, ANTHROPIC_API_KEY, OPENCLAW_SANDBOX, OPENCLAW_DOCKER_SOCKET) as part of setup examples. Requesting or configuring those keys is expected for the documented integrations, but the skill does not require them itself. Confirm you only provide secrets to services you intend to use.
Persistence & Privilege
The skill is not always-enabled and does not request elevated privileges itself. The course encourages running long-lived daemons, installing gateway services, and configuring agents that perform scheduled tasks and file edits — all legitimate for deployment guidance but they entail sustained privileges on your host if you follow the instructions.
What to consider before installing
This package is primarily documentation and a local search utility, which is coherent with its declared purpose — but treat the content as prescriptive guidance, not safe-by-default code. Things to consider before acting: - Provenance: the skill's source/homepage is unknown; prefer official docs from project homepages before running commands. Verify the origin of install scripts (openclaw.ai, ollama.com) independently. - Do not run piped install commands (curl | bash or iwr | iex) without inspecting the script. Download and read remote install scripts first. - Avoid running containers with --privileged or binding /var/run/docker.sock unless you understand the host-escape and privilege implications. These give the container near-root access to the host. - Be cautious with examples that copy binaries into system paths (sudo cp /usr/local/bin) or require sudo/systemctl — they modify system state. - The docs describe self-modifying agent patterns and programmatic file edits (read/write/edit/exec with elevated=true). Only enable such capabilities with strict approval policies and sandboxing; restrict exec host to sandbox and use allowlists. - The skill does not ask for credentials, but the docs show many env vars and API keys. Only provide keys to processes/services you trust and run on isolated accounts when possible. If you plan to use this skill as a reference: review files locally (no network execution), verify any remote URLs and scripts, and follow least-privilege practices when applying the documented installation or runtime steps.

Like a lobster shell, security has layers — review code before you run it.

latestvk97425xt81bsngwvqnf3d0c4f9837q1e
192downloads
1stars
1versions
Updated 8m ago
v1.0.0
MIT-0

openclaw-course

Searchable reference for the OpenClaw Masterclass — 7 modules covering installation, configuration, local AI, VPS deployment, security, and skill development.


When to Use

Use this skill when the user asks about:

  • Installing or configuring OpenClaw
  • Setting up SOUL.md, IDENTITY.md, USER.md, AGENTS.md, HEARTBEAT.md
  • Local AI with Ollama
  • VPS deployment and remote access
  • Security hardening
  • Cost optimization strategies
  • Creating custom skills
  • Troubleshooting gateway or connection issues
  • Agent orchestration (Codex, Claude Code, OpenCode)

Quick Reference

ModuleFileTopics
1 - Foundations01-FOUNDATIONS.mdInstallation, first setup, messaging bridges
2 - Soul Architecture02-THE-SOUL-ARCHITECTURE.mdSOUL.md, IDENTITY.md, USER.md, AGENTS.md
3 - Local Power03-LOCAL-POWER.mdOllama, voice, vision, agentic coding
4 - Context & Costs04-CONTEXT-AND-COSTS.mdCost optimization, model selection
5 - VPS Employee05-VPS-EMPLOYEE.mdVPS deployment, Tailscale, cron jobs
6 - Security06-SECURITY.mdHardening, secrets management
7 - Skills & Future07-SKILLS-AND-FUTURE.mdCreating skills, best practices

Examples

User: "How do I configure the Soul file?" → Search Module 2, return SOUL.md section with templates and examples

User: "Troubleshoot gateway not starting" → Search Module 1, return troubleshooting section with diagnostics

User: "Set up Ollama locally" → Search Module 3, return Ollama setup steps and configuration

User: "VPS deployment guide" → Search Module 5, return VPS setup instructions

User: "Cost optimization tips" → Search Module 4, return cost-saving strategies

User: "Create a custom skill" → Search Module 7, return skill development guide

User: "Security best practices" → Search Module 6, return hardening checklist


Search Keywords

Installation & Setup

  • install, installation, setup, getting started
  • gateway, start, stop, status
  • telegram, whatsapp, slack, discord, imessage
  • docker, systemd, service

Configuration Files

  • SOUL.md, soul, personality, identity
  • IDENTITY.md, who you are, name, avatar
  • USER.md, human, preferences, about me
  • AGENTS.md, rules, boundaries, red lines
  • HEARTBEAT.md, proactive, cron, schedule

Local AI

  • ollama, local model, llama, mistral
  • whisper, voice, speech, audio
  • comfyui, image generation, vision
  • codex, claude code, opencode, coding agent

VPS & Remote

  • vps, server, deploy, remote
  • tailscale, vpn, secure access
  • cron, systemd, 24/7, always on

Costs & Optimization

  • cost, pricing, budget, cheap
  • token, context, compression, summarize
  • routing, fallback, model selection

Security

  • security, harden, protect, secrets
  • ssh, firewall, fail2ban, updates
  • privacy, data, encryption

Skills Development

  • skill, create skill, custom skill
  • SKILL.md, manifest, clawhub
  • references, scripts, index.js

Usage

# Use via OpenClaw skill system
# The skill automatically searches course content based on user queries

# Or use the CLI directly:
node index.js search "how to install OpenClaw"
node index.js search "SOUL.md example"
node index.js search "VPS setup"

File Structure

skills/openclaw-course/
├── SKILL.md              # This manifest
├── index.js              # Search functionality
└── references/           # Course modules
    ├── README.md         # Course overview
    ├── 01-FOUNDATIONS.md
    ├── 02-THE-SOUL-ARCHITECTURE.md
    ├── 03-LOCAL-POWER.md
    ├── 04-CONTEXT-AND-COSTS.md
    ├── 05-VPS-EMPLOYEE.md
    ├── 06-SECURITY.md
    └── 07-SKILLS-AND-FUTURE.md

Course Overview

The OpenClaw Masterclass is a comprehensive 7-module course that teaches you to build an autonomous AI workforce:

  1. Foundations — Install OpenClaw, understand core concepts, set up messaging bridges
  2. Soul Architecture — Configure your agent's personality and operational rules
  3. Local Power — Run local AI models, add voice/vision, orchestrate coding agents
  4. Context & Costs — Optimize for cost without sacrificing capability
  5. VPS Employee — Deploy a 24/7 agent on a VPS with secure remote access
  6. Security — Harden your infrastructure and manage secrets safely
  7. Skills & Future — Create custom skills and prepare for what's next

Part of the OpenClaw Masterclass — Build Your Autonomous AI Workforce

Comments

Loading comments...