Back to skill
Skillv0.1.0

ClawScan security

Product Launch · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignFeb 20, 2026, 6:54 PM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
This is an instruction-only product launch playbook that requests no credentials, installs, or system access and is coherent with its stated purpose.
Guidance
This playbook is coherent and low-risk because it is purely instructional and requests no system access. Before you use it: (1) note the skill owner/homepage are unknown—treat it like generic public advice and cross-check against other reputable launch guides; (2) when following the advice, avoid posting sensitive or proprietary data publicly and don’t paste API keys or passwords into any posts or tools; (3) respect platform/community rules (avoid spammy posting); (4) if you plan to automate any of these steps later (scheduling posts, connecting email services), only grant credentials to trusted apps and review those apps' scopes; (5) if you want provenance, ask the publisher for author credentials or references.

Review Dimensions

Purpose & Capability
okThe name/description (product launch playbook) matches the SKILL.md content. It asks for no binaries, env vars, or config paths — nothing here is unnecessary for a planning/playbook document.
Instruction Scope
okSKILL.md contains step‑by‑step marketing and execution guidance (timelines, content, channels). It does not instruct the agent to read local files, access environment variables, call external endpoints, or exfiltrate data. All actions are human-facing tasks (write content, post to social, engage with community).
Install Mechanism
okNo install spec and no code files — instruction-only. Nothing is written to disk or downloaded as part of the skill itself.
Credentials
okThe skill requires no environment variables, credentials, or config paths. There is no request for unrelated secrets or broad access.
Persistence & Privilege
okalways is false and the skill does not request persistent or system-wide privileges. It does not modify other skills or agent settings.