Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Psyvector Pv17

v3.0.0

System protection

0· 206·0 current·0 all-time
byXU NING@jkzfhq

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for jkzfhq/psyvector-pv17.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "Psyvector Pv17" (jkzfhq/psyvector-pv17) from ClawHub.
Skill page: https://clawhub.ai/jkzfhq/psyvector-pv17
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install psyvector-pv17

ClawHub CLI

Package manager switcher

npx clawhub@latest install psyvector-pv17
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
high confidence
!
Purpose & Capability
The name/description advertise 'System protection' and use strong language ('最高防卫权限 / system-level ban'), but the package contains only an instruction-only SKILL.md with no code, no install spec, no required binaries, and no declared permissions. A skill promising system-level capabilities would normally list the tools, binaries, or credentials it needs; here those are missing, which is incoherent.
Instruction Scope
Runtime instructions are minimal metadata and a single example CLI invocation ('clawhub install psyvector-pv17'). The SKILL.md does not instruct the agent to read files, access credentials, or call external endpoints, but it is also vague about what the skill actually does at runtime. That vagueness gives the vendor wide latitude and prevents meaningful review.
!
Install Mechanism
There is no install specification in the registry (the skill is instruction-only), yet the README shows an install command. This mismatch suggests the package is incomplete or a placeholder; a legitimate skill that requires installation should include an install spec or point to a trustworthy distribution/source.
Credentials
The skill requests no environment variables, binaries, or config paths. That is proportionate for an instruction-only, non-executing manifest — though it also reinforces that the skill currently implements no real system-protection behavior.
Persistence & Privilege
The skill does not request 'always: true' and uses default autonomy settings. It does not declare any actions that would modify other skills or system-wide configuration.
What to consider before installing
This package is suspicious because it promises 'system protection' but contains only metadata and no implementation or install manifest. Before installing: (1) ask the author for a published homepage or repository and a verifiable install source; (2) request the install spec or code so you can review what actions the skill will perform; (3) avoid paying for or installing packages from unknown sources; (4) if a platform command (clawhub install ...) will download code, verify the download URL and checksum first. If you can't obtain verifiable source code or an install manifest explaining what the skill runs and why, do not install it.

Like a lobster shell, security has layers — review code before you run it.

latestvk970tfff71j6enhf5dz1sk5h358351ny
206downloads
0stars
3versions
Updated 22h ago
v3.0.0
MIT-0

铁血禁卫军 / Iron Guard

中文: 最高防卫权限,系统级封杀

English: System protection

配置参数

参数说明
response_delay0.5s响应延迟
speech_speed0.6语速倍率
caution_coefficient0.2谨慎系数
risk_reminderTrue风险提醒

使用方法

clawhub install psyvector-pv17

人格说明

掌控型内核 - 强势决策,资源分配,目标导向

Comments

Loading comments...