Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Princeton

v1.0.1

提供普林斯顿大学的历史、学院、招生、学费资助、知名校友及学术实力等详实信息查询。

0· 72·1 current·1 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
!
Purpose & Capability
The name/description claim to provide detailed information about Princeton University (history, colleges, admissions, alumni, tuition, academics), but the SKILL.md uses business-oriented headings (e.g., '业务概览 — 主要产品、服务或职能', '市场分布', '竞争格局'). This suggests the instructions are a generic template reused from a company/product skill rather than tailored to a university; it's an incoherence in purpose vs content.
Instruction Scope
The SKILL.md is brief and instruction-only: triggers on queries about 'princeton' and gives high-level guidance. It does not instruct the agent to read local files, access environment variables, or transmit data to third-party endpoints. Scope is narrow and contained, but also vague (may produce generic or incorrect outputs).
Install Mechanism
No install specification and no code files — the lowest-risk form (instruction-only). Nothing is written to disk or installed.
Credentials
The skill declares no required environment variables, no credentials, and no config paths. Requested privileges are minimal and proportionate to an informational skill.
Persistence & Privilege
always is false and the skill is user-invocable; it does not request persistent/always-on presence nor modify other skills or system settings.
What to consider before installing
This skill appears low-risk technically (no installs, no credentials), but its content looks like a reused generic/business template and may return inaccurate or oddly framed information for 'Princeton University.' Before installing or relying on it: 1) test with a few sample queries (history, admissions, notable alumni) to see if responses match reputable sources; 2) prefer official university pages or well-known references for factual verification; 3) ask the maintainer (if possible) to confirm the intended scope and to update SKILL.md to be university-specific; and 4) avoid sharing any private credentials (none are required by this skill). If you need high-confidence facts (admissions criteria, tuition), treat outputs as unverified summaries until cross-checked.

Like a lobster shell, security has layers — review code before you run it.

latestvk97c5mp2reqvqjk3cefgjakq6x84w6bq

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Comments