Back to skill
Skillv1.0.0

ClawScan security

LinkedIn Profile Optimizer · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignFeb 20, 2026, 3:31 PM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
The skill is an instruction-only LinkedIn rewrite assistant whose declared requirements and runtime instructions match its stated purpose, but it asks users to paste potentially sensitive profile text and has no publisher homepage or source for accountability.
Guidance
This skill appears to be what it claims, but before using it: (1) avoid pasting private contact details or any data you wouldn't want shared — redact phone numbers, emails, proprietary accomplishments, or client names if needed; (2) test with a redacted or dummy profile first to confirm output style; (3) note there is no homepage or publisher information — if provenance or a privacy policy matters to you, ask the publisher for those details before submitting real data; (4) remember anything you paste will be processed by the AI and may be logged by the hosting service, so treat it as shared with the platform.

Review Dimensions

Purpose & Capability
okName, description, and SKILL.md all describe a text-only LinkedIn audit and rewrite workflow; there are no unrelated environment variables, binaries, or install steps requested that would be disproportionate to that purpose.
Instruction Scope
noteInstructions only operate on user-provided profile text (headline, About, experience, etc.) and generate rewrites; this is appropriate for the stated goal. Note: the skill explicitly requires users to paste full profile content, which can include PII and sensitive career details — that is expected for the task but worth caution.
Install Mechanism
okNo install spec or code files are present (instruction-only), so nothing is written to disk or fetched during install; low installation risk.
Credentials
okThe skill requests no environment variables, credentials, or config paths — consistent with an instruction-only text-processing tool.
Persistence & Privilege
okalways is false and autonomous invocation is the platform default; the skill does not request persistent presence or system-wide configuration changes.