Social Trust Manipulation Detector
PassAudited by ClawScan on May 1, 2026.
Overview
This is a coherent instruction-only reputation-analysis skill, with no code or credential use shown, but its trust verdicts and declared command-line tools should be treated carefully.
Before installing, be aware that this skill may guide the agent to analyze marketplace social and account-activity data using curl or python3. It appears purpose-aligned and non-destructive, but its manipulation verdicts should be verified with the supporting evidence before acting on them.
Findings (2)
Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.
The agent may use command-line tools to retrieve or process marketplace data while performing the assessment.
The skill declares network and scripting tools. That is consistent with fetching and analyzing marketplace trust-signal data, and no automatic or unsafe command is shown, but users should be aware that tool use may occur during analysis.
requires:
bins: [curl, python3]Review any proposed curl or python3 commands before allowing them, especially if they access non-public data or write files.
A false positive or overconfident report could unfairly reduce trust in a legitimate skill or publisher.
The skill is designed to generate trust and manipulation labels about marketplace skills or publishers. This is purpose-aligned, but such labels can strongly affect user trust decisions if treated as authoritative.
Manipulation verdict: AUTHENTIC / SUSPICIOUS / COORDINATED / MANUFACTURED
Use the report as one input among others, and verify claims against underlying evidence before making moderation, installation, or reputational decisions.
