Back to skill
Skillv1.0.0

ClawScan security

Content Remix Studio · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignFeb 10, 2026, 5:12 PM
Verdict
Benign
Confidence
high
Model
gpt-5-mini
Summary
The skill's requirements and instructions align with its stated purpose (content repurposing) and it does not request credentials, install code, or access system resources.
Guidance
This skill is internally consistent and needs no credentials or installs. Before using, remember: (1) only provide content you are comfortable sharing with the agent (it will process whatever you paste), (2) verify any platform-specific recommendations (trending sounds, scheduling advice, policy compliance) before publishing, and (3) if you prefer the agent not call this skill autonomously, disable model invocation or restrict its use in your agent settings. If you plan to automate posting or trend queries, expect to need additional skills or integrations that will request platform API credentials.

Review Dimensions

Purpose & Capability
okName, description, and SKILL.md all describe content remixing and platform-specific outputs. There are no requested binaries, env vars, or external integrations that would be inconsistent with a text-generation/content-rewriting utility.
Instruction Scope
okThe instructions focus on transforming user-provided source content into platform-optimized variants (titles, scripts, threads, etc.). The SKILL.md does not instruct the agent to read unrelated system files, access environment variables, or send data to external endpoints. All actions described are limited to content generation and strategy guidance.
Install Mechanism
okThis is an instruction-only skill with no install spec and no code files, so nothing is written to disk and no external packages are fetched.
Credentials
okThe skill declares no environment variables, credentials, or config paths. That is proportionate for a text-based content transformation tool that operates on user-provided input.
Persistence & Privilege
noteThe skill does not set always:true (so it is not forced into every agent run). disableModelInvocation is not set, so the model can autonomously invoke this skill when eligible — this is normal for convenience but worth noting if you want to limit autonomous use.