Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Bikini Contest Photos – Create Contest-Ready Images Online – API-powered

v1.0.0

Bikini contest photos — transform a person photo into a bikini model image or video

0· 34·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
high confidence
Purpose & Capability
Name/description, declared endpoint host (openapi.weshop.ai), and the single required env var (WESHOP_API_KEY) align: this skill legitimately needs a WeShop API key to call the provider's OpenAPI endpoints.
!
Instruction Scope
SKILL.md stays within the API's domain (openapi.weshop.ai) and tells the agent to upload images and poll runs. However the default textDescription explicitly instructs 'naturally undress and change the outfit into a thin bikini', which directs generation of sexualized/explicit transformations of person photos. That behavior is ethically and legally sensitive (potential non-consensual deepfakes) and should be considered out-of-scope for many users. The doc otherwise does not ask for unrelated files or extra env vars.
Install Mechanism
No install spec and no code files — instruction-only skill (lowest install risk). Nothing is downloaded or written to disk by an installer.
Credentials
Only a single credential (WESHOP_API_KEY) is required and is the documented primary credential. The SKILL.md explicitly warns not to send the key to domains other than openapi.weshop.ai. No unrelated secrets or config paths are requested.
Persistence & Privilege
always is false, no installs, and the skill does not request system-wide configuration changes or persistent elevated privileges.
What to consider before installing
Technically the skill is coherent: it needs only a WESHOP API key and calls openapi.weshop.ai endpoints. However the skill's default instructions explicitly direct creating sexualized/undressed versions of person photos. Before installing or using it: (1) do not upload images of real people without their explicit consent; this can be illegal or ethically wrong; (2) verify the WeShop service terms, content-moderation policy, and local laws about deepfakes/sexual imagery; (3) only provide your API key if you trust openapi.weshop.ai and ensure calls go to that host (the SKILL.md warns about this); (4) consider refusing or editing out the default 'undress' textDescription if you want to avoid generating sexual or non-consensual content. If you need help assessing legal/ethical risk or sanitizing prompts, seek legal/advisory guidance before proceeding.

Like a lobster shell, security has layers — review code before you run it.

latestvk978mjh773bry1m6qvqv9syjzx84vgw3

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Runtime requirements

EnvWESHOP_API_KEY
Primary envWESHOP_API_KEY

Comments