Prometheus Fire

PassAudited by ClawScan on May 12, 2026.

Overview

This is a prompt-only self-reflection skill with no code or install step, but it asks for sensitive personal thoughts and describes an evolving personal profile, so users should be cautious about what they share.

This skill appears coherent and instruction-only, with no code, install step, credentials, or network behavior in the supplied artifacts. Before using it, remember that it asks for deeply personal thoughts, anxieties, values, decisions, and work context, and it describes ongoing profile updates. Do not share secrets or confidential details unless you are comfortable with the platform's chat, memory, and privacy handling.

Findings (3)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

The skill may lead users to disclose private personal, emotional, career, or business information into the chat context.

Why it was flagged

The skill asks the user to provide personal beliefs, anxieties, decisions, repeated mistakes, and other sensitive self-profile material so it can build the user's six thinking facets.

Skill content
你将从四个矿脉中提炼材料... 当前最让你焦虑或困扰的 2-3 件事... 你过去 2-3 个重要决策的完整过程
Recommendation

Avoid entering secrets, confidential business details, or highly sensitive personal information unless you understand how the platform stores and uses chat context and memory.

What this means

Future responses may be influenced by prior summaries or inferred traits, which can be useful but may also carry forward inaccurate or sensitive assumptions.

Why it was flagged

The skill describes repeated post-conversation summarization and updates to the user's persona, implying ongoing reuse of profile-like context.

Skill content
每次对话后:├── 系统提炼 1-3 条关键洞见 ├── 标注激活了哪个面相 └── 询问:有没有新想法/事件要补充进分身?
Recommendation

Review and correct generated profile summaries, and clear or avoid persistent memory if you do not want this information reused.

What this means

Users may share more sensitive information than they otherwise would based on a privacy claim that should be verified against the actual runtime platform.

Why it was flagged

The skill gives a strong privacy assurance, but the provided artifacts are prompt-only and do not show an enforceable local-only data mechanism.

Skill content
数据完全本地——你输入的思想材料不会离开你的设备
Recommendation

Treat the local-only statement as a claim, not a guarantee; check the platform's model, logging, and memory settings before sharing sensitive material.