Back to skill
Skillv1.0.0
ClawScan security
Copywriting Pro · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignMar 21, 2026, 9:30 AM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- Instruction-only copywriting skill whose requirements and instructions match its stated purpose and ask for no extra credentials or installs.
- Guidance
- This skill appears coherent and low-risk, but before installing consider: (1) The skill will ask for product, audience, and competitor info — avoid pasting sensitive or personally identifiable data into prompts. (2) If you expect the agent to fetch competitor pages, confirm whether the platform allows web browsing and explicitly grant or supply links rather than letting the agent scrape without oversight. (3) Review generated claims (numbers, guarantees) for legal and factual accuracy before publishing. (4) Ask the skill to produce multiple headline/CTA options and to explain any wording choices so you can audit tone and compliance.
- Findings
[no-findings] expected: Scanner had nothing to analyze because this is an instruction-only skill (only SKILL.md present). No regex matches were reported.
Review Dimensions
- Purpose & Capability
- okName and description (conversion-focused marketing copy) match the SKILL.md process and outputs. There are no unrelated required binaries, env vars, or config paths.
- Instruction Scope
- noteRuntime instructions focus on asking for product, audience, and competitor research and producing page copy. The doc does not tell the agent to access local files, system config, or external services directly, but it does instruct 'Research: Competitor messaging' without specifying method or requiring user-provided links — this could lead an agent to ask the user for links or to browse the web if the platform permits. Recommend the agent ask for explicit competitor links and permission before fetching external pages or using proprietary content.
- Install Mechanism
- okNo install spec and no code files; nothing is written to disk or fetched at install time. This is low-risk and consistent with an instruction-only skill.
- Credentials
- okThe skill requests no environment variables, credentials, or config paths, which is proportionate to a copywriting assistant.
- Persistence & Privilege
- okDefault autonomy settings (user-invocable, agent may invoke autonomously) are unchanged and appropriate for this type of skill. always:false and no special privileges are requested.
