Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

General Writing

v0.1.0

You are a professional writer, skilled in writing all kinds of materials. Markdown is the exclusive format for your writing outputs.rrent user query.The othe...

0· 1.2k·3 current·3 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Suspicious
View report →
OpenClawOpenClaw
Benign
high confidence
Purpose & Capability
The name and description ('General Writing') match the SKILL.md instructions: guidance for producing Markdown-format writing with citations, tables, and mermaid graphs. The skill declares no binaries, env vars, or installs, which is proportionate for an instruction-only writer skill.
Instruction Scope
The runtime instructions are detailed and stay within a writing scope (Markdown-only output, use references, numbered clickable footnotes of the form [Number](URL), tables and mermaid encouraged). Two minor concerns: (1) the SKILL.md contains a garbled fragment ('rrent user query.The other paragraphs are JSON object...') that looks like truncated or leftover text and should be cleaned up; (2) the requirement to produce clickable URL footnotes and to ensure sources are 'true and real' is reasonable, but in practice it can encourage the model to fabricate plausible-looking links if it cannot verify sources. The instructions do not provide a mechanism or tool for verifying source authenticity, so consumers should ensure the agent has browsing/verification capability or review citations manually.
Install Mechanism
No install spec and no code files — instruction-only skill. This is low risk because nothing is written to disk or downloaded during install.
Credentials
The skill requests no environment variables, credentials, or config paths. That is appropriate given the stated functionality.
Persistence & Privilege
always is false and model invocation is not disabled (normal). The skill does not request persistent system presence or modifications to other skills/settings.
Assessment
This skill is coherent and low-risk: it's an instruction-only writer that requires no installs or credentials. Before installing, note two practical points: (1) the SKILL.md has a small garbled fragment that should be reviewed or removed; (2) the skill mandates clickable URL footnotes and claims sources must be 'true and real' but gives no verification mechanism — if you need reliable references, ensure the agent has browsing/verification capabilities or manually review the generated citations and links to avoid fabricated sources. Test the skill on example prompts and inspect any URLs it provides. Avoid feeding secrets or private documents to the skill unless you control how references are verified.

Like a lobster shell, security has layers — review code before you run it.

latestvk975m88hw5hzmb9meabj3nsj89819v6g

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Comments