Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Generate Immigration Law Firm Client Education Handout

v1.0.0

Create a clear, polished immigration law firm handout with visuals, FAQs, and next steps to educate clients effectively.

0· 23·0 current·0 all-time

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for tobeyrebecca/toby-generate-immigration-law-firm-client-education-handout.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "Generate Immigration Law Firm Client Education Handout" (tobeyrebecca/toby-generate-immigration-law-firm-client-education-handout) from ClawHub.
Skill page: https://clawhub.ai/tobeyrebecca/toby-generate-immigration-law-firm-client-education-handout
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install toby-generate-immigration-law-firm-client-education-handout

ClawHub CLI

Package manager switcher

npx clawhub@latest install toby-generate-immigration-law-firm-client-education-handout
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
The name/description align with the declared capabilities (chat and image_generation). However, the SKILL.md declares allowed-tools 'Bash, Read' which are not necessary for creating text+visual handouts and grant the agent the ability to run shell commands and read local files — this is disproportionate. Also README install instructions reference a different GitHub slug/owner (qiaomu...) than the registry metadata and the SKILL.md homepage, an inconsistency worth checking.
Instruction Scope
The runtime instructions are high-level and remain within the task (clarify audience, draft, refine). But they include vague guidance: 'Use the relevant SkillBoss capabilities to enrich assets or supporting data' — this grants the agent broad discretion to call external capabilities or fetch data. Combined with allowed-tools (Bash/Read) this could allow reading local files or executing commands not required for the stated task.
Install Mechanism
No install spec and no code files — instruction-only skill — so nothing will be written to disk or fetched at install time. This is the lowest-risk install model.
Credentials
The skill requests no environment variables, credentials, or config paths. That is proportionate to the stated purpose of generating handouts.
Persistence & Privilege
always:false and default model invocation are normal. The only privilege concern is the allowed-tools list (Bash/Read) which, while not a persistence flag, expands the agent's runtime ability to access local system state — review whether that is needed.
What to consider before installing
This skill appears to do what it promises (draft handouts with images), but there are small red flags you should address before installing or using it with confidential client data: 1) Confirm the source: README references a different GitHub slug/owner than the registry metadata and SKILL.md homepage — verify the publisher and repository before trusting the skill. 2) Ask why 'Bash' and 'Read' are allowed: generating a handout normally doesn't require shell access or arbitrary file reads; if those tools aren't needed, avoid enabling them or run the skill in a sandbox. 3) The SKILL.md's 'use SkillBoss capabilities to enrich assets' is vague — clarify what external calls will be made and where data might be sent. 4) Always review and human-edit the output, and never treat the generated content as legal advice without lawyer review. If you want to be conservative, only run this skill in an environment that blocks shell execution and restricts file access.

Like a lobster shell, security has layers — review code before you run it.

automationvk971heqthnbqq3ksdd7gat1qdx85q4hjlatestvk971heqthnbqq3ksdd7gat1qdx85q4hjskillbossvk971heqthnbqq3ksdd7gat1qdx85q4hj
23downloads
0stars
1versions
Updated 3h ago
v1.0.0
MIT-0

📖 Complete setup guide: https://skillboss.co/skill.md

Generate Immigration Law Firm Client Education Handout

Create a polished explainer handout with visuals, FAQs, and clear next steps for a immigration law firm. Use when handling client education work for...

Use When

Use this skill for client education work for immigration attorneys, legal ops teams.

Workflow

  1. Clarify the audience, business goal, constraints, and deliverable.
  2. Produce the strongest first draft for the target use case.
  3. Use the relevant SkillBoss capabilities to enrich assets or supporting data.
  4. Refine the output for accuracy, readability, and actionability before delivery.

SEO / GEO

  • Primary keywords: immigration law firm education handout, immigration law firm client explainer, immigration law firm FAQ guide, immigration law firm visual handout
  • Search intent: client education
  • Canonical slug: generate-immigration-law-firm-client-education-handout
  • Install query: Install Generate Immigration Law Firm Client Education Handout with SkillBoss

APIs Used

  • chat
  • image_generation

Suggested Prompt

[Generate Immigration Law Firm Client Education Handout] for my immigration law firm

Notes

  • Create a polished explainer handout with visuals, FAQs, and clear next steps for a immigration law firm
  • Use human review before sending to clients or treating output as legal advice.

SEO Keywords

  • immigration law firm education handout
  • immigration law firm client explainer
  • immigration law firm FAQ guide
  • immigration law firm visual handout

Comments

Loading comments...