False positive: clawzempic #174

Open
opened 2026-02-15 17:16:02 -05:00 by yindo · 0 comments
Owner

Originally created by @naveenspark on GitHub (Feb 13, 2026).

Hi ClawHub team,

My published skill was flagged as suspicious, and I believe this is a false positive.

Skill slug: clawzempic
Versions attempted: 2.3.3, 2.3.4
Publish IDs: k97ce5en1jkqngq1rsmtnxh325815kp8, k9745dhcab3tp1by5y8zzc5xeh814nc6

Both versions publish successfully (clawhub publish returns OK), but the skill never appears in search, explore, or inspect.

What the skill is: A README for Clawzempic, an LLM API proxy that does smart routing and prompt caching. The npm package is already live: https://www.npmjs.com/package/clawzempic

Author: x.com/naveenspark

What it contains: Pure markdown. No shell scripts, no code, no executables. Just install instructions, feature descriptions, and a comparison table.

Why it's likely flagged: The skill describes a safety/guardrails feature that redacts sensitive data from tool output. We suspect keywords like "masks secrets and tokens", "sensitive data redaction", and "input validation" are triggering the scanner even though the skill itself contains zero code.

For v2.3.4 we already modified the language (removed words like "credential", "injection", "exfiltration", replaced with "safety guardrails" and "sensitive data redaction") but it's still not visible.

Could you please either:

  1. Remove the suspicious flag, or
  2. Share what rule was triggered so we can adjust the wording

Thank you for all your help!

Naveen

Originally created by @naveenspark on GitHub (Feb 13, 2026). Hi ClawHub team, My published skill was flagged as suspicious, and I believe this is a false positive. Skill slug: `clawzempic` Versions attempted: 2.3.3, 2.3.4 Publish IDs: `k97ce5en1jkqngq1rsmtnxh325815kp8`, `k9745dhcab3tp1by5y8zzc5xeh814nc6` Both versions publish successfully (`clawhub publish` returns OK), but the skill never appears in search, explore, or inspect. **What the skill is:** A README for [Clawzempic](https://clawzempic.ai), an LLM API proxy that does smart routing and prompt caching. The npm package is already live: https://www.npmjs.com/package/clawzempic **Author:** [x.com/naveenspark](https://x.com/naveenspark) **What it contains:** Pure markdown. No shell scripts, no code, no executables. Just install instructions, feature descriptions, and a comparison table. **Why it's likely flagged:** The skill describes a safety/guardrails feature that redacts sensitive data from tool output. We suspect keywords like "masks secrets and tokens", "sensitive data redaction", and "input validation" are triggering the scanner even though the skill itself contains zero code. For v2.3.4 we already modified the language (removed words like "credential", "injection", "exfiltration", replaced with "safety guardrails" and "sensitive data redaction") but it's still not visible. Could you please either: 1. Remove the suspicious flag, or 2. Share what rule was triggered so we can adjust the wording Thank you for all your help! Naveen
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: openclaw/clawhub#174