Back to skill
Skillv1.0.0
ClawScan security
Xiaohongshu Viral Content · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignMar 1, 2026, 12:15 PM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- This is an instruction-only content-generation skill whose templates, requirements, and instructions align with its stated purpose and it does not request credentials, install code, or access unrelated system data.
- Guidance
- This skill appears coherent and low-risk from a technical standpoint because it is instruction-only and asks for no credentials or installs. Before using: (1) review generated copy for accuracy, factual claims, and compliance with Xiaohongshu/community rules (avoid spammy or misleading claims); (2) do not paste sensitive or personal data into prompts (the skill will generate public-facing text); (3) treat outputs as drafts that need human editing for tone, legality, and platform policy; (4) if you need automated posting or analytics, prefer a skill that explicitly requests only the relevant service credentials and documents what it will do. Confidence is high because the package has no code, no external URLs, and no extra permissions.
Review Dimensions
- Purpose & Capability
- okName/description (Xiaohongshu viral copy generator) match the SKILL.md content: templates, headline formulas, content structure, tags, and scheduling advice. The skill declares no binaries, env vars, or installs — consistent with a copywriting/template tool.
- Instruction Scope
- okSKILL.md contains only content-generation instructions, examples, templates, and guidance for prompts. It does not instruct the agent to read files, access system paths, use environment variables, call external endpoints, or transmit data elsewhere.
- Install Mechanism
- okNo install spec and no code files are present (instruction-only). Nothing will be written to disk or downloaded during install — lowest-risk model for installation.
- Credentials
- okThe skill requests no environment variables, credentials, or config paths. There are no unrelated or excessive secret requests; requested capabilities are proportionate to a text-generation/template skill.
- Persistence & Privilege
- okalways:false (default) and user-invocable:true — normal settings. The skill does not request persistent system presence or modify other skills/configurations.
