Back to skill
Skillv1.0.2
ClawScan security
Listing Bridge Free Optimizer · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignApr 22, 2026, 2:56 PM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- This is an instruction-only Amazon listing rewriter that asks users to paste product text and returns rewritten copy; its inputs, scope, and lack of installs or credential requests are consistent with its stated purpose.
- Guidance
- This skill appears internally consistent and low-risk because it only contains prompt instructions and asks for no credentials or installs. Before using it, avoid pasting sensitive or proprietary information (supplier agreements, pricing formulas, private customer data). Test with non-sensitive examples first and review outputs for accuracy and policy compliance (Amazon listing rules, trademark/copyright issues). If you plan to use this in production or at scale, verify the developer (links point to shopclawmart and PhantomWorks) and confirm any privacy/terms before sending real customer or confidential data.
Review Dimensions
- Purpose & Capability
- okName/description (CN→EN Amazon listing optimizer) match the SKILL.md content. The skill requires no binaries, credentials, or installs — appropriate for a prompt-based text transformation tool.
- Instruction Scope
- okRuntime instructions only ask the user to paste product title, features, category, and target market or provide an English draft for improvement. There are no instructions to read files, environment variables, system paths, or to transmit data to external endpoints.
- Install Mechanism
- okNo install spec or code files are present; this is instruction-only so nothing is written to disk or downloaded at install time.
- Credentials
- okThe skill requests no environment variables, credentials, or config paths — proportional to a text rewrite task.
- Persistence & Privilege
- notealways is false (good). disable-model-invocation is false by default (the agent may call the skill autonomously), which is normal platform behavior; this is only a concern when combined with other red flags (none present here).
