Back to skill
Skillv1.0.0

ClawScan security

Tech Solution Generator · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignMar 1, 2026, 12:16 PM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
The skill is an instruction-only template for generating technical solution documents; its declared purpose matches the content and it requests no installs, credentials, or unusual privileges.
Guidance
This skill is instruction-only and coherent with its stated purpose, but consider: (1) the source/homepage is unknown — you cannot verify the author or trustworthiness beyond the provided content; (2) do not paste sensitive or confidential data (credentials, PII, proprietary architecture diagrams) into prompts — the skill will process whatever you provide; (3) treat generated technical recommendations as starting points: validate performance/security claims (e.g., availability numbers, design choices, third-party components) before implementation; (4) if you require provenance or liability guarantees, prefer skills from known authors or with a public homepage/repo.

Review Dimensions

Purpose & Capability
okName/description promise: automatic generation of technical方案 documents. SKILL.md contains templates, examples, prompts, and configurable parameters that directly implement that purpose. The skill does not request unrelated binaries, credentials, or access.
Instruction Scope
okRuntime instructions are limited to producing architecture, tech-selection, risk, and schedule text from user-provided requirements. It asks the user to paste PRD or provide textual prompts; it does not instruct the agent to read system files, environment variables, or transmit data to external endpoints.
Install Mechanism
okNo install spec and no code files — instruction-only. Nothing is written to disk or downloaded during install.
Credentials
okNo required environment variables, credentials, or config paths are declared. The functionality described does not require any external secrets or cloud credentials.
Persistence & Privilege
okalways is false and the skill is user-invocable. It does not request persistent presence or modify other skills or system settings.