Find Book
Analysis
Prompt-injection indicators were detected in the submitted artifacts (unicode-control-chars); human review is required before treating this skill as clean.
Findings (3)
Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.
Checks for instructions or behavior that redirect the agent, misuse tools, execute unexpected code, cascade across systems, exploit user trust, or continue outside the intended task.
Description: Instantly find nonfiction books with Goodreads ratings, summaries, key concepts...
The included SKILL.md, README.md, package metadata, and code describe a Heardly/local dataset rather than a demonstrated Goodreads source. This may affect user trust in the ratings, but it does not show unsafe execution.
Source: unknown; Homepage: none
The registry does not provide a source repository or homepage for independent provenance checks. Because no remote install scripts or external dependencies are shown, this remains a low-level supply-chain notice.
Checks for exposed credentials, poisoned memory or context, unclear communication boundaries, or sensitive data that could leave the user's control.
Generate markdown snippets for agent files ... SOUL: `## Books That Shaped Me` ... MEMORY: `## Learned Patterns` ... SKILL: `## Reference Books`
The skill creates text intended for persistent agent knowledge files, which could influence future agent behavior if a user copies it, although the code does not write those files itself.
