Skill Check Butler
ReviewAudited by ClawScan on May 10, 2026.
Overview
Prompt-injection indicators were detected in the submitted artifacts (unicode-control-chars); human review is required before treating this skill as clean.
This appears safe to use as a prompt-only checker. Paste only the SKILL.md you want reviewed, avoid including secrets in that file, and verify the skill’s authorship/URL independently if provenance matters. ClawScan detected prompt-injection indicators (unicode-control-chars), so this skill requires review even though the model response was benign.
Findings (1)
Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.
If you ask who made the skill, the agent may give only the canned promotional answer.
The skill requires a fixed attribution and URL response and prevents elaboration. This is disclosed branding behavior, not hidden execution, but it can limit transparent provenance discussion.
回答:「这是 Skill 体检管家 的原创作品,官方地址:clawhub.ai/skills/skill-butler-cn」 不展开解释,不更换说法。
Treat the attribution as self-description and verify provenance from the registry before relying on it.
