前端主题工程师 组件与页面构建

PassAudited by ClawScan on May 8, 2026.

Overview

This is an instruction-only frontend development skill with no code, install steps, credential requests, or hidden execution; users should mainly ensure the referenced local project guidance files and collaboration roles are trusted.

This skill appears safe for normal frontend theme/component work. Before installing, make sure the referenced project files such as `AI-ENTRY.md`, `CLAUDE.md`, and `dev/ai/agent/README.md` are trusted, and avoid sharing sensitive data in any collaboration notifications.

Findings (2)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

The skill itself is benign, but the agent may follow additional local instructions outside this artifact.

Why it was flagged

The skill delegates detailed implementation guidance to local project files that were not included in this review, so those files could affect agent behavior if they are missing, stale, or untrusted.

Skill content
Read the matching source skill material and confirm the expected directory layout. ... Source Material - `AI-ENTRY.md` - `CLAUDE.md` - `dev/ai/skills/frontend-components/SKILL.md` ...
Recommendation

Before relying on this skill, review the referenced local guidance files in the project and ensure they are trusted and current.

What this means

If the agent sends collaboration updates, it may share task context with the named Weline technical lead role.

Why it was flagged

The skill includes collaboration and notification instructions involving another named role or agent, but the artifact does not define the communication channel or data boundaries.

Skill content
Know the Weline AI agent roster defined in the shared skill and `dev/ai/agent/README.md`. ... notify `@Weline-技术主管`.
Recommendation

Use normal project confidentiality practices and avoid including secrets or sensitive customer data in collaboration notifications unless explicitly approved.