Back to skill
Skillv1.1.0
ClawScan security
twitter-cards · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignApr 5, 2026, 3:11 PM
- Verdict
- Benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- This is an instruction-only skill that provides guidance and code snippets for implementing Twitter (X) Card metadata; its requirements and instructions match its stated purpose and it does not request extra privileges or install code.
- Guidance
- This skill is low-risk: it's an offline guidance document with code examples for Twitter Card meta tags and doesn't ask for credentials or install code. Before using, verify any generated snippets fit your framework/version and test links with the official Card Validator. If you allow autonomous agent invocation, monitor first uses to ensure the agent applies recommendations only where you want them.
Review Dimensions
- Purpose & Capability
- okThe name and description (optimizing Twitter Card metadata) align with the content of SKILL.md. There are no unexpected binaries, credentials, or configuration paths requested that would be unrelated to adding or optimizing meta tags.
- Instruction Scope
- okSKILL.md contains only guidance, examples, and a link to the official Card Validator. It does not instruct the agent to read local files, access environment variables, call external endpoints other than the documented validator link, or perform actions outside metadata guidance.
- Install Mechanism
- okNo install spec and no code files — instruction-only. Nothing is downloaded or written to disk, so there is no install-related risk.
- Credentials
- okThe skill declares no required environment variables, credentials, or config paths. That is proportionate given its purpose of providing SEO/meta-tag guidance.
- Persistence & Privilege
- okThe skill is user-invocable, not always-on, and does not request elevated persistence or system-wide configuration changes. Autonomous invocation is allowed by default but not unusual here and does not combine with other risky properties.
