Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Paris Fr

v1.0.1

提供巴黎旅游景点、文化、美食、住宿和交通等实用信息,助您规划法国首都旅行和生活细节。

0· 59·1 current·1 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
high confidence
!
Purpose & Capability
The skill metadata and description advertise Paris travel information (sights, culture, food, lodging, transport), but the SKILL.md contains a brief brand/company profile for "paris-fr" (development history, product features, market distribution). These are different purposes; the requested capabilities (none) do not align with the advertised travel-guide functionality.
Instruction Scope
SKILL.md is short and narrowly scoped: it instructs the agent to '查找 paris-fr' and '了解 paris-fr 的背景' and provides a template for a brand dossier. It does not instruct reading local files, using environment variables, or contacting any particular external endpoint. Functionally harmless but does not implement the travel-guide behavior described in the skill description.
Install Mechanism
No install specification and no code files — instruction-only. This minimizes install-time risk because nothing will be downloaded or written to disk during install.
Credentials
No environment variables, credentials, or config paths requested. The skill does not ask for secrets or elevated access that would be disproportionate to either the advertised or the actual instruction content.
Persistence & Privilege
The skill is not marked always:true, and there is no indication it will modify other skills or system settings. Autonomy is allowed by default (disable-model-invocation is false) but that is normal for skills and not by itself a red flag here.
What to consider before installing
This skill is instruction-only and technically low-risk, but it appears inconsistent: the listing promises a Paris travel guide while the SKILL.md only contains a short brand/company profile for “paris-fr.” Before installing, ask the publisher which functionality is intended. If you expected travel recommendations, do not rely on this skill until it is corrected. Also note there is no homepage or provenance information (owner ID only); prefer skills with clear authorship and documentation. If you decide to proceed, monitor what the skill actually does (network calls or requests for credentials) and remove it if behavior differs from the documented purpose.

Like a lobster shell, security has layers — review code before you run it.

latestvk978qxbe94wfryza3kdrgxskg584w06z

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Comments