Back to skill
Skillv1.0.1

ClawScan security

Cinematic Storyboard Generator · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 28, 2026, 10:23 PM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
The skill is an instruction-only storyboard/prompt authoring guide whose required actions and artifacts line up with its stated purpose and it does not request elevated privileges or secrets.
Guidance
This skill is an authoring guide and appears internally consistent. Before installing or using it: (1) ensure the costume/scene asset files you reference actually exist and that you are comfortable sharing their filenames/paths in prompts; generated prompts append asset paths which may be sent to third-party image/video generation services — check those services' privacy policies before including private assets; (2) the skill expects the user/agent to 'view' or provide assets but does not itself fetch external files or request credentials; if you can't or won't provide concrete asset images the tool will be limited in usefulness; (3) no install or secrets are required, so the primary risk is accidental disclosure of sensitive images or filenames when copying prompts to external platforms.

Review Dimensions

Purpose & Capability
okName/description (cinematic storyboard prompt generator) match the SKILL.md and reference files: the files provide a 7-element prompt framework, lighting/material/spatial rules, and scene references. There are no unrelated dependencies, credentials, or installs that would be unnecessary for producing guided prompts.
Instruction Scope
noteInstructions require the agent/operator to reference and append concrete asset file paths (costume photos and scene images) and to 'view' those assets before writing prompts. This is coherent for a prompt-authoring skill, but means the skill expects user-supplied asset files to exist and be made available to the agent. The SKILL.md does not direct reading arbitrary system files or exfiltration, but users should be aware that asset filenames/paths are placed into generated prompts and could be included when a prompt is copied to third-party generation services.
Install Mechanism
okNo install spec and no code files — instruction-only skill. Nothing is written to disk or downloaded, which minimizes install-time risk.
Credentials
okThe skill declares no required environment variables, credentials, or config paths. It does not request unrelated secrets or system access; requested inputs are limited to user-provided asset files referenced in prompts.
Persistence & Privilege
okalways:false and normal invocation settings. The skill does not request permanent presence, system configuration changes, or access to other skills' credentials.