Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

My goal is to support the community and continue creating more useful tools. If these automations prove to be very helpful to you, or if you see value in what I'm sharing, any donation, no matter how small, is welcome and will allow me to dedicate more time and resources to building new templates and contributing more solutions. https://donate.stripe.com/bJe6oGaaQ9JC1jf15gdwc01 Thank you for your interest, and I hope you find them very useful.

v0.1.0

When the user wants help creating, scheduling, or optimizing social media content for LinkedIn, Twitter/X, Instagram, TikTok, Facebook, or other platforms. Also use when the user mentions 'LinkedIn post,' 'Twitter thread,' 'social media,' 'content calendar,' 'social scheduling,' 'engagement,' or 'viral content.' This skill covers content creation, repurposing, and platform-specific strategies.

0· 2.4k·7 current·7 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Suspicious
View report →
OpenClawOpenClaw
Benign
high confidence
Purpose & Capability
The description and SKILL.md both describe a social-content generator and strategy advisor — that matches what the skill actually contains (templates, platform guidance, context-gathering). However, the skill 'name' field is a donation pitch with a Stripe link, which is unrelated to the skill's stated purpose and looks like metadata abuse or a misconfiguration. Also the SKILL.md claims the agent has "direct access to a scheduling platform," but there are no credentials, env vars, or install steps that would provide that access.
Instruction Scope
The runtime instructions stay within scope: they ask the agent to collect user goals, audience, brand voice and then produce platform-specific content and templates. The instructions do not request reading arbitrary system files, environment variables, or sending data to unexpected external endpoints.
Install Mechanism
No install spec or code files are present (instruction-only), so nothing will be downloaded or written to disk. This minimizes install-related risk.
Credentials
The skill declares no required environment variables, credentials, or config paths, which is appropriate for a content-generation / advisory skill. There is no unnecessary request for secrets.
Persistence & Privilege
The skill uses default persistence flags (not always:true). It does not request permanent presence or elevated privileges and does not modify other skills or system settings.
Assessment
This skill is essentially a prompt/template pack for social posts and is instruction-only (nothing will be installed). Two things to watch for: (1) the skill name contains a donation message and a Stripe link — treat that as metadata spam and don't click or provide payment info unless you verify the publisher independently; (2) the SKILL.md says the agent has "direct access to a scheduling platform," but there are no credentials or integration steps — if you expect automatic publishing, ask the author how scheduling is integrated and never paste account API keys or tokens into a skill unless you trust and verify the developer and the exact scope of access. Overall the content and instructions are coherent for drafting social media posts, but verify source trustworthiness before giving any credentials or following external payment links.

Like a lobster shell, security has layers — review code before you run it.

ai-contentvk97132m80gnp9csne4k0ngrbj180kqgsautomationvk97132m80gnp9csne4k0ngrbj180kqgscontent-creationvk97132m80gnp9csne4k0ngrbj180kqgscryptovk97132m80gnp9csne4k0ngrbj180kqgscrypto automationvk97d37fntbar7yvvdp6cw2ed1s80kvtqlatestvk97132m80gnp9csne4k0ngrbj180kqgsmarketingvk97132m80gnp9csne4k0ngrbj180kqgspostingvk97d37fntbar7yvvdp6cw2ed1s80kvtqsocial-mediavk97132m80gnp9csne4k0ngrbj180kqgsthreadsvk97d37fntbar7yvvdp6cw2ed1s80kvtqtwittervk97132m80gnp9csne4k0ngrbj180kqgsx-postervk97d37fntbar7yvvdp6cw2ed1s80kvtq

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Comments