Back to skill
Skillv1.0.0
ClawScan security
Build Operations Faq Page · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignApr 22, 2026, 7:22 AM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- This is an instruction-only FAQ content generator whose declared requirements and instructions are consistent with its stated purpose.
- Guidance
- This skill appears coherent for drafting FAQ content. Before installing, confirm what "relevant SkillBoss capabilities" will be invoked (to ensure they won't access corporate files or secrets), test outputs locally, and review any generated customer-facing text for accuracy and compliance before publishing. If you want to prevent autonomous calls to other platform capabilities, restrict or monitor skill invocation in your agent settings.
Review Dimensions
- Purpose & Capability
- okName, description, and declared capabilities (chat, web_search) match a content-generation FAQ skill. No unrelated binaries, credentials, or config paths are requested.
- Instruction Scope
- noteSKILL.md contains a narrow workflow for drafting and refining FAQ content. One vague item—"Use the relevant SkillBoss capabilities to enrich assets or supporting data"—could implicitly permit the agent to call other SkillBoss features; verify what those capabilities are and whether they access external or sensitive data before enabling them.
- Install Mechanism
- okInstruction-only skill with no install spec or code files, so nothing is written to disk or fetched during install.
- Credentials
- okNo environment variables, credentials, or config paths are required; requested permissions are proportionate to generating FAQ content.
- Persistence & Privilege
- okSkill is not marked always:true and uses default autonomous invocation. This is normal for skills; it does not request elevated persistence or to modify other skills.
