Back to skill
Skillv1.0.0
ClawScan security
thesis-introduction-writer · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignApr 28, 2026, 6:05 PM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- The skill is an instruction-only Chinese thesis-introduction writer whose inputs, files, and runtime instructions are coherent with its stated purpose and request no unrelated privileges or secrets.
- Guidance
- This skill appears coherent and low-risk: it only drafts Chinese introduction chapters and uses an included reference guide. Before installing, consider: (1) provide clear, complete study details (title, method, population, etc.) so the output won’t rely on placeholders for citations or specifics; (2) the draft will include citation placeholders unless you explicitly ask the agent to fetch exact sources—if you request that, the agent may perform browsing/network calls; (3) always review drafts for accuracy, plagiarism, and alignment with your institution's policies; and (4) avoid supplying sensitive or confidential participant data to the skill. If you want the skill to fetch or cite real papers, ask how it will obtain sources and verify any retrieved references.
Review Dimensions
- Purpose & Capability
- okThe name and description match the SKILL.md and reference material: the skill only targets writing/structuring thesis introduction chapters in Chinese. It requests no unrelated binaries, environment variables, or credentials and only uses a local reference file (references/introduction-writing-guide.md) that is directly relevant.
- Instruction Scope
- okSKILL.md narrowly instructs the agent to extract user-supplied study details, consult the included reference, draft introduction sections, use placeholders for missing citations, and avoid producing other chapters. It does not direct reading of unrelated system files, exfiltration, or transmission to external endpoints. The only network-related guidance ('Browse only when the user asks for current sources or exact references') is conditional on an explicit user request.
- Install Mechanism
- okNo install spec and no code files beyond instruction/reference documents. As instruction-only content, nothing is downloaded or executed and nothing is written to disk by an installer.
- Credentials
- okThe skill declares no required environment variables, credentials, or config paths. The SKILL.md does not reference hidden environment variables or request secrets.
- Persistence & Privilege
- okalways is false and the skill does not request permanent system presence or modification of other skills. disable-model-invocation is false (normal) but there are no accompanying broad privileges or sensitive access that would raise concern.
