Back to skill
Skillv1.0.0
ClawScan security
Build Orthopedic Physical Therapy Practice Service Comparison Landing Page · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignApr 22, 2026, 12:24 PM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- The skill is internally consistent with its stated purpose: it is an instruction-only content-generation helper for orthopedic physical therapy landing pages and requests no installs, credentials, or unusual system access.
- Guidance
- This skill appears coherent and low-risk from a platform-access standpoint, but remember: (1) do not feed any patient-identifiable or sensitive health data into it, (2) have a qualified clinician review any medical claims or patient-facing language before publishing, (3) confirm which SkillBoss capabilities (image_generation, ui_generation, or others) the agent may call when enriching assets and ensure those integrations are acceptable, and (4) validate SEO/price/claim language for regulatory compliance in your jurisdiction before use.
Review Dimensions
- Purpose & Capability
- okName/description align with the SKILL.md: the instructions, keywords, and workflow all focus on producing conversion-focused landing page copy and assets for orthopedic physical therapy. The skill does not request unrelated binaries, environment variables, or config paths.
- Instruction Scope
- noteThe SKILL.md stays within content-generation tasks (clarify audience, draft content, refine, SEO). Step 3's instruction to “Use the relevant SkillBoss capabilities to enrich assets or supporting data” is somewhat vague and could cause the agent to invoke other platform capabilities or pull external assets; this is not inherently malicious but you should confirm which capabilities/data sources will be used and avoid sending any patient-identifiable information (PHI). The file explicitly advises human review for patient-facing or regulated medical claims, which is appropriate.
- Install Mechanism
- okNo install spec and no code files — instruction-only skill. This minimizes disk-write and supply-chain risk.
- Credentials
- okThe skill declares no required environment variables, no credentials, and no config paths. This is proportionate to a copy-and-asset generation skill.
- Persistence & Privilege
- okThe skill does not request always: true and uses default invocation settings. It does not ask to modify other skills or system configs.
