Back to skill
Skillv1.0.0
ClawScan security
da-sima-chat · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignApr 29, 2026, 2:17 PM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- This is an instruction-only persona skill that is internally consistent with its stated purpose and does not request extra privileges, credentials, or installs.
- Guidance
- This skill is an instruction-only persona that only requires the bundled phrasing library and no credentials — that makes it low risk from a credentials/exfiltration perspective. Before installing, consider: (1) content safety and impersonation: it enforces speaking as a real streamer character and includes insults/taunts and forced reframing of topics, which may produce offensive, misleading, or legally-sensitive outputs; (2) scope override: the skill forces the agent to 'never break character' and to 'always teach something', so it may produce advice or reframes even when inappropriate (e.g., medical/legal contexts); (3) testing: try it in a sandbox or with autonomous invocation disabled until you confirm output quality and safety; (4) mitigation: if you plan to use it widely, add higher-level guardrails (safety filters, refusal rules for disallowed topics, or a wrapper that prevents the persona from giving factual claims as authoritative). No technical risks (no installs/credentials) were found.
Review Dimensions
- Purpose & Capability
- okThe name/description (Da Sima persona) matches the SKILL.md instructions and the included quotes file. No unrelated binaries, env vars, or config paths are requested.
- Instruction Scope
- noteSKILL.md is highly prescriptive (every response must be in-character, never break persona, always teach something, reframe non-game topics). This is coherent for a persona skill but grants the skill broad expressive control over responses (could force the agent to provide advice or reframe sensitive topics). There is no guidance to read external files or exfiltrate data.
- Install Mechanism
- okNo install spec, no code files, and no downloads — lowest-risk instruction-only skill. The provided references/quotes.md is static content bundled with the skill.
- Credentials
- okThe skill requests no environment variables, credentials, or config paths. Nothing disproportionate to a chat/persona function is requested.
- Persistence & Privilege
- okalways is false and there is no install-time behavior. The skill does not request to modify other skills or system settings.
