Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Payment Term Negotiator

v1.0.0

Provides frameworks and templates for negotiating payment terms with structured analysis, actionable recommendations, and next steps guidance.

0· 89·1 current·1 all-time
byhaidong@harrylabsj

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for harrylabsj/payment-term-negotiator.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "Payment Term Negotiator" (harrylabsj/payment-term-negotiator) from ClawHub.
Skill page: https://clawhub.ai/harrylabsj/payment-term-negotiator
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install payment-term-negotiator

ClawHub CLI

Package manager switcher

npx clawhub@latest install payment-term-negotiator
Security Scan
Capability signals
CryptoCan make purchases
These labels describe what authority the skill may exercise. They are separate from suspicious or malicious moderation verdicts.
VirusTotalVirusTotal
Pending
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
Name, description, and provided files align: this is a descriptive finance/negotiation helper that returns structured JSON and templates. Required env vars/binaries/configs are none, which is consistent with its stated purpose.
!
Instruction Scope
SKILL.md repeatedly states 'No real code execution' and 'No external API calls', but the bundle includes an executable handler.py and tests that will run locally if invoked. The Python code itself performs only local parsing and JSON generation (no network, no file writes), but the presence of executable code contradicts the 'instruction-only / no execution' claim and could be run by an agent or user.
Install Mechanism
No install spec is provided (instruction-only). No downloads or third-party packages are required. This is low-risk from an installation standpoint.
Credentials
The skill requests no credentials, environment variables, or config paths. The code does not access environment variables or external services. Requested privileges are minimal and proportionate.
Persistence & Privilege
always is false and agent invocation is default (allowed). The skill does not request persistent system presence or modify other skills/config — no elevated privileges detected.
What to consider before installing
This skill appears to implement what it advertises (local analysis and templates) and does not request credentials or network access. However, the SKILL.md asserts 'no code execution' while the package includes an executable handler.py and unit tests. Before installing or enabling autonomous use: (1) manually review handler.py and tests (they look benign: local parsing and JSON output, no network/file writes); (2) if you do not want code executed, ensure the agent is not allowed to run local files or restrict execution in policy; (3) run the code in an isolated sandbox to confirm behavior; (4) verify the publisher/trust (source is unknown); and (5) if you expect a purely instruction-only skill, ask the author to remove executable code or make that explicit. These steps will reduce risk and clarify intent.

Like a lobster shell, security has layers — review code before you run it.

latestvk9728t0437ahwh0nk4cnjx5pm5854n80
89downloads
0stars
1versions
Updated 1w ago
v1.0.0
MIT-0

Payment Term Negotiator

Overview

Provides payment term negotiation frameworks. This is a descriptive skill that provides frameworks and templates without executing real code.

Safety

  • No real code execution
  • No external API calls
  • No financial transactions
  • Informational only

Outputs

  • Structured analysis
  • Actionable recommendations
  • Next steps checklist

Comments

Loading comments...