Back to skill
Skillv1.0.0

ClawScan security

Social Media content writing · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignMar 19, 2026, 11:47 AM
Verdict
Benign
Confidence
high
Model
gpt-5-mini
Summary
The skill is an instruction-only guide for multi‑platform content creation and operations and its requirements, instructions, and lack of installs/credentials are consistent with that purpose.
Guidance
This skill is an instructional playbook — benign and coherent. Before granting any agent actions based on these instructions, confirm what concrete integrations it will use: if the agent asks for social‑platform credentials or API tokens to post or fetch analytics, only provide least‑privilege tokens or use a sandbox account. Be cautious about enabling autonomous posting or account linkage; ask the skill/agent to show proposed posts and request explicit approval before publishing. Also be mindful that some suggested tactics (舆论引导, rapid amplification) have ethical and platform policy implications.

Review Dimensions

Purpose & Capability
okName, description, and SKILL.md all describe multi‑platform content production, distribution, analytics and user operations; there are no unrelated environment variables, binaries, or install steps requested.
Instruction Scope
noteSKILL.md is a prose guide describing planning, content adaptation, metrics, tools and crisis response. It does not instruct the agent to read system files, use specific credentials, or call external endpoints directly, but it is somewhat high‑level: real execution (posting, analytics pulls) would require separate integrations or user‑provided credentials. The instructions give broad discretion (e.g., 'utilize tools' and 'data‑driven decisions'), so at runtime the agent may ask for account access or perform network actions if enabled by the platform.
Install Mechanism
okNo install spec and no code files — instruction‑only skill means nothing is written to disk or downloaded during install.
Credentials
okSkill declares no required environment variables, credentials, or config paths; nothing requested appears disproportionate to the stated purpose.
Persistence & Privilege
okalways is false and model invocation is allowed (platform default). The skill does not request persistent presence or system configuration changes.