Back to skill
Skillv1.0.0

ClawScan security

Content Writer · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignFeb 19, 2026, 6:43 PM
Verdict
Benign
Confidence
high
Model
gpt-5-mini
Summary
The skill is internally consistent with its stated purpose (multi-platform content generation); it requests no credentials, has no install or code, and its runtime instructions stay within content-generation scope.
Guidance
This skill appears coherent and low-risk from a system-access perspective: it needs no credentials, has no install, and only contains content-generation instructions. Before installing or using: 1) verify the skill owner if you need provenance (no homepage provided), 2) test outputs in a sandbox or draft mode before posting publicly (the 'provocative' tone can produce harmful or policy-violating content), 3) review generated content for accuracy, copyright, privacy, and platform policy compliance, and 4) if you require stronger guarantees, prefer skills with a known author/homepage or those published by trusted sources.

Review Dimensions

Purpose & Capability
okName, description, and commands all describe content generation; there are no unexpected required binaries, env vars, or config paths. The declared capabilities (tweets, threads, posts, product listings, newsletters, bios, hooks) match the instructions.
Instruction Scope
noteSKILL.md purely instructs how to generate platform-optimized content and includes platform-specific formatting rules. It does not direct the agent to read files, access credentials, or transmit data to external endpoints. Note: it explicitly allows 'provocative' tone and strong opinions — this can lead to policy- or reputation-risk (offensive/defamatory content) if not moderated, but this is a content-moderation concern rather than incoherence.
Install Mechanism
okInstruction-only skill with no install spec and no code files. Nothing is written to disk and no third-party packages or downloads are requested.
Credentials
okNo environment variables, credentials, or config paths are required. The skill does not request access to unrelated services or secrets.
Persistence & Privilege
okalways is false and autonomous invocation is allowed (the platform default). There is no request to persist or modify other skills or system-wide settings.