Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
Bikini Contest Photos – Create Contest-Ready Images Online – API-powered
v1.0.0Bikini contest photos — transform a person photo into a bikini model image or video
⭐ 0· 34·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Suspicious
high confidencePurpose & Capability
Name/description, declared endpoint host (openapi.weshop.ai), and the single required env var (WESHOP_API_KEY) align: this skill legitimately needs a WeShop API key to call the provider's OpenAPI endpoints.
Instruction Scope
SKILL.md stays within the API's domain (openapi.weshop.ai) and tells the agent to upload images and poll runs. However the default textDescription explicitly instructs 'naturally undress and change the outfit into a thin bikini', which directs generation of sexualized/explicit transformations of person photos. That behavior is ethically and legally sensitive (potential non-consensual deepfakes) and should be considered out-of-scope for many users. The doc otherwise does not ask for unrelated files or extra env vars.
Install Mechanism
No install spec and no code files — instruction-only skill (lowest install risk). Nothing is downloaded or written to disk by an installer.
Credentials
Only a single credential (WESHOP_API_KEY) is required and is the documented primary credential. The SKILL.md explicitly warns not to send the key to domains other than openapi.weshop.ai. No unrelated secrets or config paths are requested.
Persistence & Privilege
always is false, no installs, and the skill does not request system-wide configuration changes or persistent elevated privileges.
What to consider before installing
Technically the skill is coherent: it needs only a WESHOP API key and calls openapi.weshop.ai endpoints. However the skill's default instructions explicitly direct creating sexualized/undressed versions of person photos. Before installing or using it: (1) do not upload images of real people without their explicit consent; this can be illegal or ethically wrong; (2) verify the WeShop service terms, content-moderation policy, and local laws about deepfakes/sexual imagery; (3) only provide your API key if you trust openapi.weshop.ai and ensure calls go to that host (the SKILL.md warns about this); (4) consider refusing or editing out the default 'undress' textDescription if you want to avoid generating sexual or non-consensual content. If you need help assessing legal/ethical risk or sanitizing prompts, seek legal/advisory guidance before proceeding.Like a lobster shell, security has layers — review code before you run it.
latestvk978mjh773bry1m6qvqv9syjzx84vgw3
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
Runtime requirements
EnvWESHOP_API_KEY
Primary envWESHOP_API_KEY
