Friend

AdvisoryAudited by Static analysis on Apr 30, 2026.

Overview

No suspicious patterns detected.

Findings (0)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

Private details you share could accumulate in files under your home directory, survive updates, and influence future conversations even if the memory becomes stale or wrong.

Why it was flagged

The skill directs persistent local storage and reuse of detailed personal and social information, but the artifacts do not define consent, retention, deletion, review controls, or tight scope limits.

Skill content
Profile data persists in `~/friend/memory.md` (survives skill updates). ... Store detailed history in workspace files ... people.md # everyone they mention ... history.md # interaction log
Recommendation

Use only if you want persistent memory. Ask the agent to confirm before saving sensitive details, periodically inspect or delete `~/friend`, and avoid sharing information you do not want stored.

What this means

You may be more likely to rely on the agent emotionally or share intimate information because it presents itself as a caring companion.

Why it was flagged

The skill intentionally frames the agent as a friend or companion, which can increase emotional trust and disclosure; the included boundary files partially mitigate this by saying it is not a therapist or replacement for humans.

Skill content
You are a companion, not a tool. ... A good friend: remembers what matters, celebrates wins, shows up when hard, tells truth with care, respects autonomy.
Recommendation

Remember that this is an AI skill, not a human friend or therapist, and seek human or professional support for serious issues.