Back to skill
Skillv1.0.0

ClawScan security

Short Drama Emotion Curve · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 28, 2026, 11:32 PM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
This is an instruction-only creative skill for designing short-drama emotional arcs; its requirements and instructions are consistent with that purpose and it does not request credentials or install code.
Guidance
This skill appears coherent and low-risk technically: it only provides creative patterns and templates and does not request credentials or install code. Before installing, consider non-technical concerns: (1) provenance — the skill has no homepage or identifiable author, so verify trust if you depend on it commercially; (2) copyright — ensure you have rights to reuse any example scripts or references; (3) ethical use — the guidance explicitly teaches how to design "pain points" and emotional manipulation for viewers — consider whether that aligns with your content policy and platform rules and avoid targeting or exploiting vulnerable groups; (4) data handling — if you or the agent feed user-specific or personal data into the skill (e.g., real names, private stories), treat that data carefully even though the skill itself doesn't transmit it. If you want higher assurance, ask the publisher for author identity, licensing, and any test cases showing expected outputs.
Findings
[no_regex_findings] expected: The static scanner had no findings because this is an instruction-only skill with no executable code; that is expected for a content/design skill.

Review Dimensions

Purpose & Capability
okName, description, and included documentation all describe emotional-arc design for 60–90s short dramas; there are no unexpected binaries, env vars, or external integrations requested.
Instruction Scope
okSKILL.md and reference documents contain only creative guidance, templates, shot and pacing advice. They do not instruct the agent to read system files, access environment variables, call external endpoints, or exfiltrate data.
Install Mechanism
okNo install spec and no code files — the skill is instruction-only, so nothing is written to disk or installed.
Credentials
okThe skill declares no required environment variables, credentials, or config paths; requested access is proportional (none) to the stated creative purpose.
Persistence & Privilege
okalways is false and autonomous invocation is default; the skill does not request forced persistence or modify other skills or system settings.