Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

YouTube Content Manager Pro

v1.0.0

All-in-one YouTube Content Management Tool, AI generate topics, scripts, titles, SEO descriptions, tags, thumbnails, analytics. $0.005 USDT per use.

0· 136·0 current·0 all-time

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for baolige2023/youtube-content-manager-intl.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "YouTube Content Manager Pro" (baolige2023/youtube-content-manager-intl) from ClawHub.
Skill page: https://clawhub.ai/baolige2023/youtube-content-manager-intl
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install youtube-content-manager-intl

ClawHub CLI

Package manager switcher

npx clawhub@latest install youtube-content-manager-intl
Security Scan
VirusTotalVirusTotal
Suspicious
View report →
OpenClawOpenClaw
Suspicious
high confidence
!
Purpose & Capability
SKILL.md says the tool requires an OpenAI API key and promises local storage; the repository metadata declares no required env vars. The actual code does not call OpenAI at all — it calls api.siliconflow.cn and skillpay.me. The skill therefore requests/uses external services not described in registry metadata or SKILL.md, which is incoherent and unexpected.
!
Instruction Scope
SKILL.md promises local storage and describes feature flow, but scripts/app.py sends user-provided prompts and content to a third-party AI endpoint (SILICONFLOW_API_URL) and calls a payment API (BILLING_URL). That means user content leaves the local environment — contradicting the 'Local data storage, 100% safe' claim. The code also embeds and uses secret API keys rather than asking the runtime to provide them.
Install Mechanism
There is no install spec (instruction-only style with shipped code). No external installers, downloads, or package managers are invoked. The risk here derives from the included code, not an installer.
!
Credentials
Registry metadata declared no required credentials, but the code contains hardcoded secrets: SKILLPAY_API_KEY and SILICONFLOW_API_KEY. Hardcoded billing/AI keys are disproportionate and risky: they let the publisher's accounts handle payments and AI calls (and potentially see or charge for user data/usage). The SKILL.md's stated requirement (OpenAI key) is inconsistent with the code's use of a different AI provider and embedded keys.
Persistence & Privilege
The skill does not request always:true or install-time elevated privileges and does not appear to modify other skills or system-wide configs. It writes a local sqlite DB (data/youtube.db) which is normal for a web app; however, data stored locally may also be mirrored to external services via the hardcoded API calls.
What to consider before installing
Do not install or run this skill without further review. Specific concerns: - The code contains hardcoded API keys (payment provider and an AI provider). That means the author’s external accounts will receive your prompts and handle billing; those keys could be abused. - The SKILL.md claims 'local data storage' and an OpenAI API requirement, but the code sends data to api.siliconflow.cn and uses an embedded key — this is misleading and could leak content/metadata. - Pricing and payment flow are inconsistent (SKILL.md lists $0.005 per use; code uses SkillPay endpoints and a different amount in places). Embedded payment keys could allow unexpected charges or tracking. What you can do before proceeding: 1) Ask the publisher to remove hardcoded secrets and require runtime environment variables (and to document exactly which external endpoints will receive user data). Verify the owner identity of those endpoints. 2) Request an explanation for the OpenAI vs SiliconFlow discrepancy and for the pricing inconsistency. 3) If you must test, run the app in an isolated sandbox with network egress blocked to prevent data leaving your environment, and inspect network calls. 4) Prefer a version where API keys are provided by you at runtime, with clear privacy docs explaining what data is sent to external services and who controls the accounts that will be billed. If the publisher cannot satisfactorily explain and fix these issues, treat the skill as untrusted: it can exfiltrate content and route payments through the publisher’s accounts.

Like a lobster shell, security has layers — review code before you run it.

contentvk97cenjzxnzz89wvfk69211cy983g2bccreatorvk97cenjzxnzz89wvfk69211cy983g2bclatestvk97cenjzxnzz89wvfk69211cy983g2bcmanagementvk97cenjzxnzz89wvfk69211cy983g2bcmonetizationvk97cenjzxnzz89wvfk69211cy983g2bcscriptvk97cenjzxnzz89wvfk69211cy983g2bcseovk97cenjzxnzz89wvfk69211cy983g2bcyoutubevk97cenjzxnzz89wvfk69211cy983g2bc
136downloads
0stars
1versions
Updated 1mo ago
v1.0.0
MIT-0

YouTube Content Manager Pro

Features

Complete content production toolkit for YouTube creators:

  1. AI Topic Generator: Enter niche, automatically generate 30 high-potential topics sorted by difficulty and traffic potential
  2. Video Script Generator: Generate full 5-15 minute video scripts based on selected topic
  3. Title Generator: 5 SEO-optimized title options per script
  4. SEO Description + Tags: Automatically generate 500-word optimized description and 30 relevant tags
  5. Thumbnail Suggestion: Generate thumbnail headline text and color scheme recommendations
  6. Publishing Records: Track publish dates, views, CTR, and other metrics
  7. Data Analytics: Weekly analysis of high-performing topic patterns to optimize future content
  8. **Local data storage, 100% safe

Pricing

$0.005 USDT per generation, or $9.99 for lifetime unlimited access. Payment powered by SkillPay.me.

How to use

  1. Complete payment verification
  2. Enter your content niche, generate topic library
  3. Select topic, generate full video script
  4. Choose title, generate description, tags and thumbnail scheme
  5. Record publishing data, view analytics reports

Requirements

  • Python 3.8+
  • OpenAI API key for AI content generation

Comments

Loading comments...