Back to skill
Skillv1.0.0

ClawScan security

thesis-title-generator · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 29, 2026, 5:57 AM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
The skill is an instruction-only thesis title generator whose requested resources and instructions align with its stated purpose and do not ask for unrelated credentials, installs, or system access.
Guidance
This skill appears coherent and limited to its stated purpose, but review these practical points before installing or using it: - Privacy: the skill asks for full thesis text; avoid submitting embargoed, confidential, or sensitive data (proprietary results, unpublished code, participant data, etc.). - Academic integrity: do not share material that violates advisor or institutional policies (e.g., unpublished coauthor material or restricted datasets) without permission. - Verify outputs: the guide explicitly warns against fabricating results; nevertheless, check recommended titles against your thesis and advisor requirements (formatting, required phrases, length limits, bilingual equivalence, and school rules). - Export/Sharing: the skill package is instruction-only and contains no hidden endpoints, but using it will involve sending your text to whatever LLM/service the agent uses — confirm you are comfortable with that provider's data handling. - If you need broader automation (batch processing, institutional integration), expect additional permissions or services to be required; reassess at that point. Overall this skill is internally consistent; main non-technical risk is exposing your full manuscript content to the model/service when you use the skill.

Review Dimensions

Purpose & Capability
okThe name and description (generate 3 bilingual thesis titles) match the SKILL.md and the included reference guide. The skill requires no binaries, environment variables, or external services — everything it needs (the title-generation guide) is bundled. There are no requests for unrelated privileges or credentials.
Instruction Scope
okRuntime instructions are narrowly scoped: read the user-supplied thesis content and the bundled references/title-generation-guide.md, extract relevant thesis elements, and produce three Chinese-English title pairs with justifications. The SKILL.md explicitly forbids fabricating findings or methods and does not instruct the agent to read unrelated files, env vars, or send data to unexpected endpoints.
Install Mechanism
okNo install spec or code files are provided (instruction-only), so nothing is written to disk or downloaded. This is the lowest-risk install profile.
Credentials
okThe skill declares no environment variables, credentials, or config paths. The requested inputs are user-provided thesis text and the local reference file included in the package — proportional to the stated function.
Persistence & Privilege
okThe skill is not marked 'always' and is user-invocable only. It does not request system-wide configuration or modify other skills. Autonomous model invocation is allowed by platform default but is not a special privilege here.