Social Trust Manipulation Detector

PassAudited by ClawScan on May 1, 2026.

Overview

This is a coherent instruction-only reputation-analysis skill, with no code or credential use shown, but its trust verdicts and declared command-line tools should be treated carefully.

Before installing, be aware that this skill may guide the agent to analyze marketplace social and account-activity data using curl or python3. It appears purpose-aligned and non-destructive, but its manipulation verdicts should be verified with the supporting evidence before acting on them.

Findings (2)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

The agent may use command-line tools to retrieve or process marketplace data while performing the assessment.

Why it was flagged

The skill declares network and scripting tools. That is consistent with fetching and analyzing marketplace trust-signal data, and no automatic or unsafe command is shown, but users should be aware that tool use may occur during analysis.

Skill content
requires:
      bins: [curl, python3]
Recommendation

Review any proposed curl or python3 commands before allowing them, especially if they access non-public data or write files.

What this means

A false positive or overconfident report could unfairly reduce trust in a legitimate skill or publisher.

Why it was flagged

The skill is designed to generate trust and manipulation labels about marketplace skills or publishers. This is purpose-aligned, but such labels can strongly affect user trust decisions if treated as authoritative.

Skill content
Manipulation verdict: AUTHENTIC / SUSPICIOUS / COORDINATED / MANUFACTURED
Recommendation

Use the report as one input among others, and verify claims against underlying evidence before making moderation, installation, or reputational decisions.