Back to skill
Skillv1.0.0

ClawScan security

Build Orthopedic Physical Therapy Practice Service Comparison Landing Page · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 22, 2026, 12:24 PM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
The skill is internally consistent with its stated purpose: it is an instruction-only content-generation helper for orthopedic physical therapy landing pages and requests no installs, credentials, or unusual system access.
Guidance
This skill appears coherent and low-risk from a platform-access standpoint, but remember: (1) do not feed any patient-identifiable or sensitive health data into it, (2) have a qualified clinician review any medical claims or patient-facing language before publishing, (3) confirm which SkillBoss capabilities (image_generation, ui_generation, or others) the agent may call when enriching assets and ensure those integrations are acceptable, and (4) validate SEO/price/claim language for regulatory compliance in your jurisdiction before use.

Review Dimensions

Purpose & Capability
okName/description align with the SKILL.md: the instructions, keywords, and workflow all focus on producing conversion-focused landing page copy and assets for orthopedic physical therapy. The skill does not request unrelated binaries, environment variables, or config paths.
Instruction Scope
noteThe SKILL.md stays within content-generation tasks (clarify audience, draft content, refine, SEO). Step 3's instruction to “Use the relevant SkillBoss capabilities to enrich assets or supporting data” is somewhat vague and could cause the agent to invoke other platform capabilities or pull external assets; this is not inherently malicious but you should confirm which capabilities/data sources will be used and avoid sending any patient-identifiable information (PHI). The file explicitly advises human review for patient-facing or regulated medical claims, which is appropriate.
Install Mechanism
okNo install spec and no code files — instruction-only skill. This minimizes disk-write and supply-chain risk.
Credentials
okThe skill declares no required environment variables, no credentials, and no config paths. This is proportionate to a copy-and-asset generation skill.
Persistence & Privilege
okThe skill does not request always: true and uses default invocation settings. It does not ask to modify other skills or system configs.