Back to skill
Skillv1.0.0

ClawScan security

thesis-discussion-writer · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 28, 2026, 6:05 PM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
The skill is an instruction-only Chinese discussion-chapter writer whose required files and instructions match its stated purpose and request no extra permissions or installs.
Guidance
This skill appears coherent and limited to writing discussion chapters. Before using it, provide the actual Results/findings, theory, and any school formatting requirements (the skill warns it will not invent findings). Avoid pasting confidential or unpublished participant-identifying data. Verify the generated text for factual accuracy, compliance with your institution's academic integrity rules, and any required citation/attribution. Because the skill is an agent instruction, the model could still hallucinate—always review and correct the draft before submission.

Review Dimensions

Purpose & Capability
okName and description claim to draft discussion chapters; the skill is instruction-only and asks only that the agent read the included guidance file and user-supplied findings. There are no unrelated binaries, credentials, or config paths requested.
Instruction Scope
okSKILL.md confines the agent to writing discussion sections, explicitly forbids inventing results or new analyses, and instructs use of the included references. It asks the agent to rely on user-provided findings or produce a template with placeholders if none are supplied — scope is narrow and appropriate.
Install Mechanism
okNo install spec and no code files that would be written or executed. Instruction-only skills have minimal disk/network risk; the included reference files are local and part of the skill bundle.
Credentials
okNo required environment variables, credentials, or config paths. There is no disproportionate request for secrets or unrelated service access.
Persistence & Privilege
okalways is false and disable-model-invocation is the default (model may invoke autonomously). This is the platform default and is reasonable for an invocable writing helper; the skill does not request persistent or cross-skill configuration changes.