Skill Trust Decision

pr-description-gen

SKILL.md 仅包含营销内容,无实际代码实现,功能描述极度模糊,存在文档欺骗嫌疑

Install decision first Source: ClawHub Scanned: 15 days ago
Files 1
Artifacts 4
Violations 0
Findings 3

Why this conclusion was reached

0/4 dimensions flagged
Pass
Declared vs actual capability

Declared resources and inferred behavior are broadly aligned.

Review
Hidden execution and egress

4 lower-risk artifacts were extracted and still need context.

Pass
Attack chain and severe findings

There is no explicit malicious chain in the report.

Review
Dependencies and supply chain hygiene

Dependency information is incomplete, so supply-chain confidence stays limited.

What drove the risk score up

文档欺骗 - 功能描述模糊 +15

核心功能仅用「智能处理」「多格式」等空泛词汇描述,无技术细节

无实际代码实现 +10

声称能生成PR描述但未提供任何可执行脚本,仅有营销文档

营销推广内容占比过高 +10

85%内容为付费版本推广和 affiliate 链接

Most important evidence

Medium Doc Mismatch

功能描述极度模糊

SKILL.md 声称能「从 git diff 和提交历史自动生成 PR 描述」,但核心功能仅用「Core automation」「Smart processing」「Batch support」「Multi-format」等空泛词汇描述,无任何技术实现细节

SKILL.md:22
应提供具体技术说明,如使用的 API、算法或命令行工具
Low Doc Mismatch

无实际代码实现

技能包仅包含 SKILL.md 文档,缺少 scripts/ 目录及任何可执行代码,无法验证声明的功能是否真正实现

SKILL.md:1
提供实际可执行的脚本代码(Python/Bash/Node.js)
Low Sensitive Access

元数据声明需要 bash 但无实际使用说明

metadata.openclaw.requires.bins 声明需要 bash,但 SKILL.md 中未说明如何使用 bash 实现声称的功能

SKILL.md:6
补充 bash 在该技能中的具体用途说明

Declared capability vs actual capability

Filesystem Pass
Declared NONE
Inferred NONE
无脚本文件,无法推断实际能力

Suspicious artifacts and egress

Medium External URL
https://kingai.work/

SKILL.md:12

Medium External URL
https://my.racknerd.com/aff.php?aff=20179

SKILL.md:53

Medium External URL
https://j.moomoo.com/0CrlDz

SKILL.md:54

Info Email
[email protected]

SKILL.md:20

Dependencies and supply chain

There are no structured dependency warnings.

File composition

1 files · 85 lines
Markdown 1 files · 85 lines
Files of concern · 1
SKILL.md Markdown · 85 lines
功能描述极度模糊 · 无实际代码实现 · 元数据声明需要 bash 但无实际使用说明 · https://kingai.work/ · https://my.racknerd.com/aff.php?aff=20179 · https://j.moomoo.com/0CrlDz · [email protected]

Security positives

无恶意代码(无可执行脚本)
无凭证窃取行为
无网络外传数据
无外部 affiliate 恶意链接