Back to skill
Skillv1.0.0
ClawScan security
social-media-viral-title-generator · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignApr 19, 2026, 3:10 AM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- Instruction-only skill that generates social-media titles; its requests and instructions are consistent with its described purpose and it does not ask for credentials, installs, or unusual system access.
- Guidance
- This skill is instruction-only and internally consistent with its stated purpose, but consider these practical points before installing: 1) Source is unknown — verify you trust the owner before enabling the skill in an agent that can act autonomously. 2) Don't provide sensitive or proprietary content as inputs (the skill will generate titles based on whatever you send). 3) The CTR scoring is conceptual — treat scores as heuristics and validate outputs against platform rules and your own data. 4) If your agent has tooling that can post directly to social platforms, review which credentials are available to the agent — this skill itself does not ask for them, but posts could occur through other configured integrations. 5) Test generated titles for originality and compliance (avoid misleading clickbait or content that violates platform policies).
Review Dimensions
- Purpose & Capability
- okName and description match the SKILL.md content: the skill's sole purpose is to generate multiple title alternatives, platform-tailored tips, and scoring/optimization suggestions. It does not request unrelated binaries, environment variables, or external services, which is appropriate for this capability.
- Instruction Scope
- okSKILL.md contains templates, examples, parameters, and scoring dimensions but does not instruct the agent to read local files, access environment secrets, or transmit data to external endpoints. The scoring methodology is described at a high level (weights) but implementation detail is intentionally omitted — this is a content-generation instruction set, which is in-scope.
- Install Mechanism
- okNo install spec and no code files — lowest-risk form. Nothing will be downloaded or written to disk by the skill itself.
- Credentials
- okThe skill declares no required environment variables, credentials, or config paths. There are no requested secrets or permissions beyond normal agent invocation, which is proportionate to its stated function.
- Persistence & Privilege
- okFlags are default (not always:true). The skill is user-invocable and allows model invocation (platform default). It does not request permanent presence or modify other skills or system settings.
