Back to skill
Skillv1.0.0

ClawScan security

朋友圈文案生成器 · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 29, 2026, 2:32 AM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
This is an instruction-only Chinese "朋友圈文案生成器" skill whose declared purpose (generating social post copy) matches its instructions and it requests no installs, binaries, or credentials.
Guidance
This skill appears internally consistent and low-risk because it is instruction-only and requires no credentials or installs. Before using: (1) test outputs for accuracy and tone, (2) ensure generated promotional content complies with local laws and platform rules (e.g., advertising disclosure), and (3) watch for future versions that add external network calls, install scripts, or request API keys/config paths—those would be a red flag.

Review Dimensions

Purpose & Capability
okName/description match the SKILL.md: the skill is a copywriter for social posts and the instructions only describe generating multi-style copy, emojis, timing, image and interaction suggestions. No unrelated capabilities or credentials are requested.
Instruction Scope
okSKILL.md contains only content/format guidance for generating posts (styles, scenarios, output fields). It does not instruct the agent to read files, access environment variables, call external endpoints, or exfiltrate data.
Install Mechanism
okNo install spec or code files are present; this is instruction-only so nothing is written to disk or installed during setup.
Credentials
okNo environment variables, credentials, or config paths are required. The requested scope is proportional to a text-generation helper.
Persistence & Privilege
okSkill is not forced-always and uses default invocation settings. It does not request persistent or system-wide privileges.