Back to skill
Skillv0.1.0
ClawScan security
Aibrary Book Recommend · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignMar 5, 2026, 1:25 PM
- Verdict
- Benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- Instruction-only skill that gives tailored book recommendations; it requests no credentials, installs nothing, and its runtime instructions are consistent with its stated purpose.
- Guidance
- This is a low-risk, instruction-only recommendation skill that asks only for the user's reading/preferences context and does not access credentials or install code. Before enabling, consider: (1) the skill source/homepage is unknown—if provenance matters, prefer skills with a known publisher; (2) avoid entering sensitive personal data when testing; (3) test with a few sample prompts to confirm the style and quality of recommendations match your expectations. Because it runs only as instructions with no external access, there are no hidden network or credential risks identified.
Review Dimensions
- Purpose & Capability
- okName, description, and SKILL.md all describe personalized book recommendations; there are no unrelated environment variables, binaries, or config paths requested.
- Instruction Scope
- okSKILL.md contains only guidance for building a reader profile, selecting 1-3 books, giving rationale and reading strategy, and asking clarifying questions when needed — it does not instruct the agent to read files, access system state, call external endpoints, or exfiltrate data.
- Install Mechanism
- okNo install spec and no code files — nothing will be downloaded or written to disk by the skill.
- Credentials
- okThe skill requires no environment variables, credentials, or config paths; requested inputs are user-provided contextual details (interests, career stage, recent reads), which are appropriate for personalization.
- Persistence & Privilege
- okalways is false and the skill does not request persistent or elevated privileges; autonomous invocation is allowed (platform default) but the skill has no added persistent presence or system modifications.
