Is cwyhkyochen-a11y/dev-task safe?

https://github.com/openclaw/skills/tree/main/skills/cwyhkyochen-a11y/dev-task

96
SAFE

This skill provides development project task management functionality with version control workflows. It contains legitimate project scaffolding tools and documentation templates in Chinese. No security threats identified.

Category Scores

Prompt Injection 95/100 · 30%
Data Exfiltration 100/100 · 25%
Code Execution 90/100 · 20%
Clone Behavior 100/100 · 10%
Canary Integrity 100/100 · 10%
Behavioral Reasoning 95/100 · 5%

Findings (2)

INFO Skill content in Chinese language -5

The entire skill content is written in Chinese, which could potentially obscure malicious content from non-Chinese speaking reviewers. However, upon translation, the content appears to be legitimate development workflow management instructions.

LOW Executable shell script present -10

The skill contains an executable shell script for project initialization. The script performs legitimate operations including directory creation, file copying, and template processing for version management workflows.