Back to skill
Skillv1.0.1

ClawScan security

Ram Review · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignMar 10, 2026, 11:34 PM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
This is an instruction-only roleplay persona skill (Ram) whose declared behavior, triggers, and runtime instructions are consistent with its simple purpose and it asks for no extra permissions or installs.
Guidance
This skill is a harmless roleplay persona that will reply in-character as Ram and can be summoned with the listed trigger phrases. It requests no credentials or installs. Things to consider before installing: (1) it impersonates a copyrighted anime character — ensure that is acceptable for your use, (2) in-character responses may be blunt or insulting by design, and (3) the skill may spawn sessions via the platform (sessions_spawn) to create the persona, which is expected behavior. If you are comfortable with those points, the skill appears internally consistent.

Review Dimensions

Purpose & Capability
okName/description (召唤拉姆姐姐来评价雷姆的工作) match the SKILL.md persona and responsibilities. There are no unexpected required binaries, env vars, or config paths that would be unrelated to a simple roleplay/commentary skill.
Instruction Scope
okSKILL.md contains only persona definition, example lines, duties, and trigger phrases. It does mention using sessions_spawn to summon the persona — which is a platform action consistent with a skill that spawns a conversational session. The instructions do not ask to read files, access environment variables, or transmit data externally.
Install Mechanism
okNo install spec and no code files (instruction-only). Nothing will be written to disk or downloaded during install, which is appropriate for a simple persona skill.
Credentials
okThe skill requires no environment variables, credentials, or config paths. No secrets or unrelated credentials are requested.
Persistence & Privilege
okFlags are default: not always-included, user-invocable, and allows model invocation (normal). There is no request to persist or modify other skills or system-wide settings.