Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Sydney Au

v1.0.1

提供悉尼旅游、文化、餐饮、住宿和交通信息,助你规划澳大利亚最大城市的旅行和生活。

0· 66·1 current·1 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
high confidence
!
Purpose & Capability
The skill description promises Sydney travel, culture, dining, lodging and transport information, but the SKILL.md is a short brand-profile template about a "sydney-au" brand (development history, products, market). This mismatch means the skill may not provide the functionality users expect or may be mislabelled.
!
Instruction Scope
SKILL.md contains only a small 'read_when' trigger and a brand-profile summary; it does not instruct the agent to gather travel-specific data, call external travel APIs, or access system files. The instructions are vague and do not align with the stated purpose, giving the skill broad, unclear scope for how it will be used.
Install Mechanism
No install specification and no code files (instruction-only). This minimizes risk from downloads or writing code to disk.
Credentials
The skill requests no environment variables, credentials, or config paths. There is no evidence of disproportionate secret access.
Persistence & Privilege
always is false and default invocation settings apply. The skill requests no elevated or persistent privileges and does not modify other skills or system settings.
What to consider before installing
This skill appears functionally mislabelled: the description promises a Sydney travel guide but the runtime instructions are a generic brand-profile template. Technical risk is low (no install, no credentials), but the skill likely won't do what you expect. Before installing or enabling it: 1) Contact the publisher or check the marketplace listing for an updated SKILL.md or correct description. 2) If you need a travel assistant, prefer a skill whose instructions explicitly show how travel data is obtained. 3) Avoid granting any credentials (none are requested now) and test the skill in a non-critical context first. 4) If you installed it expecting travel features and it behaves differently, remove it or disable it and report the mismatch to the platform.

Like a lobster shell, security has layers — review code before you run it.

latestvk9771fkafnym2p4yfkjt3e55f584w9tw

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Comments