Back to skill
Skillv1.0.0

ClawScan security

荣格思维视角 · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 29, 2026, 2:25 PM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
The skill's declared purpose (roleplay as a Jungian perspective) matches its instructions and included reference material; it is instruction-only, requests no credentials, and has no install footprint.
Guidance
This skill is internally coherent: it contains detailed role instructions and research material and asks for no secrets or installs. Before installing, note two practical points: (1) It instructs the agent to speak in the voice of C. G. Jung in first person and only shows a disclaimer once at first activation — if you want repeated reminders that responses are a constructed perspective (not the historical person), ask the skill author to make the disclaimer recurring or more prominent. (2) The skill gives psychological framing and may offer interpretive guidance; it is not a substitute for professional mental-health care. If you plan to use it for sensitive clinical or legal situations, consider adding explicit safety/disclaimer text and restricting autonomous invocation. Otherwise the skill appears proportionate to its described purpose.
Findings
[no_regex_findings] expected: The static regex scanner found nothing to analyze; this is expected because the skill is instruction-only (no executable code files or install steps).

Review Dimensions

Purpose & Capability
okName and description promise a Jung perspective and the skill contains a detailed SKILL.md and supporting reference documents that implement that purpose. There are no unrelated environment variables, binaries, or config paths requested.
Instruction Scope
noteRuntime instructions are explicit: the agent must respond in first person as Jung, use cautious language, give a one-time disclaimer on first activation, and only exit role on explicit user request. This is coherent with the stated purpose, but note the one-time disclaimer behavior — subsequent conversation will not automatically repeat that the responses are a perspective rather than the historical figure; the skill also instructs to avoid meta-analysis unless the user explicitly asks to stop roleplay, which limits the agent's normal fallback behavior.
Install Mechanism
okNo install specification and no code files to execute. Instruction-only skills with bundled reference docs present minimal installation risk.
Credentials
okThe skill requires no environment variables, credentials, or config paths. The reference files are local and self-contained, so the requested privileges are proportionate to its stated function.
Persistence & Privilege
okalways is false and there are no indications the skill requests permanent system-level presence or modifies other skills or agent config. Autonomous invocation is allowed by platform default but is not combined with elevated privileges or extra credentials here.