Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

General Search Agent

v0.1.0

Provides general search capabilities with enhanced results using English queries and current date context for accuracy.

0· 702·1 current·1 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Suspicious
View report →
OpenClawOpenClaw
Benign
high confidence
Purpose & Capability
Name/description (general search helper) match the content: a short instruction about using Google with English queries and including the current date. Nothing required by the skill (no env, no binaries) is out of scope.
Instruction Scope
SKILL.md contains only a brief guideline and template-variable mentions ($DATE, $SESSION_GROUP_ID). It's vague and minimal but stays within the claimed purpose. The vagueness means the agent's actual search implementation (not provided) will determine behavior.
Install Mechanism
No install spec and no code files — lowest-risk configuration. Nothing is written to disk or fetched at install time.
Credentials
Requires no environment variables, credentials, or config paths. There is no disproportionate access requested.
Persistence & Privilege
Skill is not always-on and does not request elevated persistence or modify other skills. Autonomous model invocation remains platform-default and is not a special privilege here.
Assessment
This skill is essentially a short instruction/template: it gives a reminder to include the current date and to favor English queries for Google searches. It requests no permissions and installs nothing, so it poses minimal direct risk. However, it's also low-utility by itself — it does not implement search or connect to any search API. Before installing, decide whether you expected a skill that actually executes queries (which would typically require a web tool or API credentials). If you plan to let your agent perform web searches, verify how your agent/runtime performs those searches (browser/tool, third-party API) and whether that component needs separate review or credentials.

Like a lobster shell, security has layers — review code before you run it.

latestvk97asn4px1p44xpqb49v84qxcs819pqm

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Comments