Back to skill
Skillv1.0.0

ClawScan security

Copywriting Pro · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignMar 21, 2026, 9:30 AM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
Instruction-only copywriting skill whose requirements and instructions match its stated purpose and ask for no extra credentials or installs.
Guidance
This skill appears coherent and low-risk, but before installing consider: (1) The skill will ask for product, audience, and competitor info — avoid pasting sensitive or personally identifiable data into prompts. (2) If you expect the agent to fetch competitor pages, confirm whether the platform allows web browsing and explicitly grant or supply links rather than letting the agent scrape without oversight. (3) Review generated claims (numbers, guarantees) for legal and factual accuracy before publishing. (4) Ask the skill to produce multiple headline/CTA options and to explain any wording choices so you can audit tone and compliance.
Findings
[no-findings] expected: Scanner had nothing to analyze because this is an instruction-only skill (only SKILL.md present). No regex matches were reported.

Review Dimensions

Purpose & Capability
okName and description (conversion-focused marketing copy) match the SKILL.md process and outputs. There are no unrelated required binaries, env vars, or config paths.
Instruction Scope
noteRuntime instructions focus on asking for product, audience, and competitor research and producing page copy. The doc does not tell the agent to access local files, system config, or external services directly, but it does instruct 'Research: Competitor messaging' without specifying method or requiring user-provided links — this could lead an agent to ask the user for links or to browse the web if the platform permits. Recommend the agent ask for explicit competitor links and permission before fetching external pages or using proprietary content.
Install Mechanism
okNo install spec and no code files; nothing is written to disk or fetched at install time. This is low-risk and consistent with an instruction-only skill.
Credentials
okThe skill requests no environment variables, credentials, or config paths, which is proportionate to a copywriting assistant.
Persistence & Privilege
okDefault autonomy settings (user-invocable, agent may invoke autonomously) are unchanged and appropriate for this type of skill. always:false and no special privileges are requested.