Back to skill
Skillv1.0.0

ClawScan security

Content Agency — AI 内容创作专家团 · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignMar 10, 2026, 2:08 AM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
The skill does what it says — multi-role content creation — and is instruction-only with no installs, credentials, or unusual privileges requested.
Guidance
This skill appears internally consistent and low-risk because it is instruction-only and requests no credentials or installs. Before using it, consider: (1) provenance — the author/homepage are unknown, so prefer testing on non-sensitive prompts first; (2) do not paste secrets, private PII, or proprietary product details into prompts; (3) review generated content for factual accuracy, unintended claims, legal/compliance or platform-rule violations, and copyright/plagiarism; (4) verify tone/brand fit and any localization/platform-specific requirements (WeChat, 小红书 rules, etc.); (5) if you plan autonomous runs, monitor outputs initially to ensure the agent's automatic role selection and publishing behavior match your expectations.

Review Dimensions

Purpose & Capability
okName/description (multi-role content agency) align with the SKILL.md instructions. It requests no binaries, env vars, or config paths that would be unrelated to content creation. Source/homepage are unknown (no provenance), but that is a transparency issue, not a technical mismatch.
Instruction Scope
noteSKILL.md contains detailed runtime instructions: choose a role, declare the role, and produce publish-ready content for various platforms. It does not instruct the agent to read local files, access environment variables, call external endpoints, or collect system data. The guidance to produce "complete publishable" content gives the agent broad creative discretion (possible risks: hallucination, undesired tone, or inadvertent inclusion of copyrighted/sensitive content).
Install Mechanism
okNo install spec; instruction-only skill — nothing is written to disk and no third-party packages are fetched.
Credentials
okNo environment variables, credentials, or config paths are required. The skill does not request access to unrelated services or secrets.
Persistence & Privilege
okalways:false (normal). The skill may be invoked autonomously by the agent (platform default), which is expected for a skill of this type. It does not request system-wide changes or modify other skills' configs.