Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
AI Lingerie Models – Generate Realistic Lingerie Visuals Online – API-powered
v1.0.0AI lingerie models — transform a person photo into a bikini model image or video
⭐ 0· 19·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Suspicious
medium confidencePurpose & Capability
Name and description match the declared requirement (WESHOP_API_KEY) and the SKILL.md documents endpoints on openapi.weshop.ai for running jobs and uploading images. There are no unrelated env vars or binaries requested.
Instruction Scope
The SKILL.md instructs uploading local images and calling openapi.weshop.ai endpoints (expected). However it contains a default textDescription that explicitly says to 'naturally undress and change the outfit into a thin bikini' and to make the model 'dance' — this enables creation of sexualized edits of person photos. There are no instructions or safeguards about obtaining consent, verifying age, or not processing images of minors, and the skill will lead agents to read and upload potentially sensitive local image files. That absence of privacy/consent controls is a substantive risk.
Install Mechanism
Instruction-only skill with no install spec and no code files — lowest install risk. Nothing is downloaded or written to disk by an installer.
Credentials
Only a single environment variable (WESHOP_API_KEY) is required and is declared as the primary credential, which is proportionate for an API-backed skill. The SKILL.md explicitly warns to only send the key to openapi.weshop.ai. Still: given the sensitive nature of the data (personal photos), users should verify the API key scope, provider policies, and data retention practices before supplying credentials.
Persistence & Privilege
always:false and no system-level installs or config changes. The skill does not request persistent/system privileges or modify other skills.
What to consider before installing
This skill appears to be functionally consistent with contacting openapi.weshop.ai using a WESHOP_API_KEY, but there are important privacy, legal, and abuse considerations you should weigh before installing:
- Source verification: the registry entry has no homepage/source metadata; confirm you trust we shop.ai and that https://openapi.weshop.ai is the real service and has an acceptable privacy policy and terms.
- Sensitive data: the skill will prompt the agent to upload local personal photos to a third-party API. Do not upload images that contain minors, private or intimate content you don't fully own/consent to share, or anything you wouldn't want stored by the vendor.
- Consent & legality: the default prompt encourages removing clothes / sexualized edits. Ensure you have explicit, verifiable consent from subjects and that creating such images is legal in your jurisdiction.
- API key safety: only provide WESHOP_API_KEY if you trust the provider. Prefer a scoped or expendable key, and never paste the key into unknown domains. The SKILL.md says the key should only be sent to openapi.weshop.ai — honor that.
- Autonomous behavior: the skill can be invoked by agents; consider disabling autonomous invocation for this skill or requiring explicit user confirmation before any upload/generation to avoid automatic exfiltration of images.
- If you proceed: verify provider data retention and deletion policies, test with non-sensitive images or mock data first, and consider using a throwaway account/key.
Given the combination of unknown source, potential for processing highly sensitive images, and missing safeguards for consent/age, exercise caution — the skill is coherent technically but carries meaningful privacy and abuse risks.Like a lobster shell, security has layers — review code before you run it.
latestvk97ehbehs4pz00h8jxm0med5jx84ry2y
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
Runtime requirements
EnvWESHOP_API_KEY
Primary envWESHOP_API_KEY
