Back to skill
Skillv1.0.3
ClawScan security
APEX-AGENT: Cognitive Upgrade for AI Agents · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignMar 6, 2026, 8:13 PM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- This is an instruction-only, session-scoped cognitive/style guideline for agents; it requires no credentials, binaries, or installs and its requirements align with its stated purpose.
- Guidance
- This skill is coherently described and low-risk from a permissions/installation perspective because it only provides response-style guidelines and asks for nothing extra. Before enabling it for sensitive workflows (legal, medical, financial, high-security), test it on representative prompts to confirm it still includes necessary safety/legal cautions; disable it if you observe missing or truncated warnings. Remember the skill changes the agent's tone and decisiveness — monitor for unwanted brevity or omission of nuance in high-stakes responses. If you need absolute assurance, install it in a non-production session first and review outputs.
Review Dimensions
- Purpose & Capability
- okName/description promise a cognitive framework and the skill is only a set of response guidelines (SKILL.md, README, EXAMPLES). No env vars, binaries, installs, or config paths are requested — everything requested or present is appropriate for a behavior/style skill.
- Instruction Scope
- noteSKILL.md contains behavioral rules that change how the agent answers (lead with value, pick a single recommendation, avoid repetitive disclaimers, cognitive modes). There are no instructions to read files, access env vars, call external endpoints, or run system commands. The one wording that could be misread — “SAFETY OVERRIDE — always active, no exceptions” — explicitly clarifies it does not suppress required safety/legal/medical warnings; still, because it promotes decisiveness and reduced hedging, users should watch outputs in high-stakes domains to ensure necessary cautions are preserved.
- Install Mechanism
- okNo install spec or code files that would write or execute code on disk; instruction-only skills are the lowest-install risk. README suggests an install command for the platform (clawhub install apex-agent) but that refers to platform skill activation, not an external download.
- Credentials
- okThe skill requires no environment variables, credentials, or config paths. There is no disproportionate credential or secret access requested.
- Persistence & Privilege
- okalways:false (session-scoped) and user-invocable:true. The skill does not request elevated platform privileges or modify other skills. It is allowed to be invoked autonomously (disable-model-invocation:false), which is the platform default and expected for useful skills.
