Back to skill
Skillv1.0.0

ClawScan security

English Speaking & Writing Coach · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 16, 2026, 2:35 AM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
An instruction-only English tutoring skill whose files, instructions, and requirements are coherent with its stated purpose and do not request extra privileges or credentials.
Guidance
This skill is content-only and internally coherent: it asks for no credentials and installs nothing, so technical risk is low. Before installing, consider: (1) provenance — the source/homepage is unknown, so review sample outputs for quality and bias; (2) privacy — anything you paste will be processed by the agent/service, so avoid submitting sensitive personal or proprietary text; (3) correctness — AI editing can be stylistic, so verify critical corrections yourself; (4) autonomous invocation — the platform allows skills to be invoked by agents by default; if you prefer manual control, disable autonomous use in your agent settings. Overall, there are no technical red flags.

Review Dimensions

Purpose & Capability
okThe name/description match the SKILL.md and reference files (grammar, fluency, IELTS/TOEFL, speaking practice). There are no unrelated binaries, env vars, or config paths requested — everything is proportional to a language tutor.
Instruction Scope
okSKILL.md provides step-by-step tutoring workflows, templates, and static reference content. It does not instruct the agent to read arbitrary system files, access environment variables, call external endpoints, or exfiltrate data.
Install Mechanism
okNo install spec and no code files to execute; the skill is instruction-only and only includes static reference markdown, which minimizes filesystem and execution risk.
Credentials
okThe skill declares no required environment variables, credentials, or config paths. The requested privileges (none) are appropriate for the described functionality.
Persistence & Privilege
okalways:false (default) and no requests to modify other skills or system settings. The skill may be invoked autonomously by the agent (platform default), which is normal for skills of this type.