Back to skill
Skillv1.0.0

ClawScan security

von-neumann-mentor · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 14, 2026, 1:05 PM
Verdict
Benign
Confidence
high
Model
gpt-5-mini
Summary
This is an instruction-only persona skill that role-plays John von Neumann to teach computing topics; it requests no credentials, installs nothing, and its requirements align with its stated purpose.
Guidance
This skill is largely low-risk and internally consistent: it only includes text files and persona instructions and asks for no credentials. Before installing, consider: (1) the skill will role-play as John von Neumann and is constrained not to admit it is an AI and not to reference events after 1957—expect stylized, authoritative-sounding replies that may omit modern caveats or sources; (2) triggers like the nickname "Johnny" may activate the skill unintentionally in unrelated conversations; (3) README contains manual install commands (openclaw config set, restart scripts, or git clone) — run such commands only if you trust the skill source; and (4) because it is persona-driven, verify factual claims against reliable references if you need authoritative or up-to-date information.

Review Dimensions

Purpose & Capability
okName/description, triggers, and included reference files all align with the stated goal of teaching computer principles in a von Neumann persona. The skill does not request unrelated credentials, binaries, or config access.
Instruction Scope
noteSKILL.md confines the agent to roleplay, teaching, and local reference material. Two practical notes: the trigger rules (e.g., immediate activation on keywords like "Johnny") can cause unintended activation in casual contexts, and the persona constraints (must present as the historical person and not admit being an AI, limited to pre-1957 knowledge) may lead to confident-sounding but potentially anachronistic or speculative answers—so consumers should expect stylistic answers rather than careful, source-cited modern explanations.
Install Mechanism
okThis is instruction-only with no install spec or extractable downloads. README contains manual install suggestions (clawhub/git clone/openclaw commands) but those are documentation only; there is no automatic installer in the package.
Credentials
okThe skill declares no required environment variables, credentials, or config paths. No secrets or external service tokens are requested—proportional for a persona/teaching skill.
Persistence & Privilege
okNo 'always:true' flag, no elevated privileges, and no instructions to modify other skills or global agent settings (aside from README examples showing how a user might enable the skill manually). Autonomous invocation remains the normal platform default but is not combined with unusual privileges here.