Back to skill
Skillv1.0.0

ClawScan security

Ask · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignMar 8, 2026, 5:54 PM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
This is an instruction-only 'thinking partner' skill that contains question frameworks and follow-up heuristics and does not request credentials, binaries, installs, or access to system resources.
Guidance
This skill is instruction-only and appears coherent with its stated purpose. It does not request credentials or install code. Consider that using the skill will involve you sharing whatever context or personal information you provide in prompts — avoid disclosing secrets (passwords, private keys, or highly sensitive personal data). If you plan to enable autonomous invocation for agents that may use this skill, be aware the agent could prompt users with follow-ups derived from your data; lock down autonomous behavior if that is a concern.

Review Dimensions

Purpose & Capability
okName and description match the contents: SKILL.md provides question taxonomies, decision frameworks, and prompts for reframing. There are no unexpected requirements (no env vars, no binaries, no external integrations).
Instruction Scope
okInstructions are limited to asking clarifying/reframing/decision questions and guidance on when to act. They do not instruct the agent to read system files, call external endpoints, or collect unrelated data.
Install Mechanism
okNo install spec and no code files. Because it's instruction-only, nothing is written to disk or fetched during install.
Credentials
okThe skill declares no environment variables, credentials, or config paths and the runtime instructions do not reference any. Requested access is proportional to the stated purpose (none required).
Persistence & Privilege
okalways is false and defaults apply. The skill does not request persistent or elevated privileges, nor does it modify other skills or system configuration.