Back to skill
Skillv1.0.0
ClawScan security
Web Coder · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignMar 5, 2026, 1:22 AM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- The skill is an instruction-only web development reference/assistant whose requirements and contents align with its stated purpose and request no unusual privileges or installs.
- Guidance
- This skill is an instruction-only web development expert with embedded reference docs and no install or credential requests — generally low risk. Before using, remember: any code snippets it generates should be reviewed before running in your environment; do not paste secrets into prompts; and if you later author automation that executes generated shell/Node code, review that automation carefully. Because the skill can be invoked autonomously by the agent (platform default), review any agent workflows that will run code produced by this skill to avoid accidental execution of unsafe commands.
Review Dimensions
- Purpose & Capability
- okName and description match the delivered assets (SKILL.md + many domain-specific reference files). The skill requests no binaries, env vars, or config paths that would be unrelated to being a web development advisor.
- Instruction Scope
- okSKILL.md instructs the agent to act as an expert web developer and points to internal reference docs. It does not direct the agent to read unrelated system files, access external endpoints, or exfiltrate secrets. There are no runtime commands or open-ended instructions that grant broad discretionary data collection.
- Install Mechanism
- okNo install spec and no code files to execute. This instruction-only skill writes nothing to disk and does not download external code.
- Credentials
- okThe skill declares no required environment variables, credentials, or config paths; the references and instructions do not access secrets. Requested privileges are proportional (none) to the stated functionality.
- Persistence & Privilege
- okalways is false and the skill does not request persistent system changes. Model invocation is allowed (platform default) which is appropriate for an assistant skill and is not combined with broad privileges.
