Back to skill
Skillv1.0.0

ClawScan security

xuanxuan-10agents · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 25, 2026, 4:03 AM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
The skill is an instruction-only role for providing traditional Chinese 'Yijing' / feng shui style advice; its requested inputs and behaviors match that purpose and it doesn't ask for unrelated system access or credentials.
Guidance
This skill appears internally consistent for providing traditional Yijing/feng shui style advice. Before installing: 1) Be aware it will prompt for personal data (name, birthdate, participant zodiacs); only share what you are comfortable providing and avoid highly sensitive identifiers (national ID numbers, full addresses, payment info). 2) The skill is instruction-only and makes no external calls or credential requests according to the provided files, but confirm runtime platform rules (e.g., whether agents log or transmit conversation history externally) if you have privacy concerns. 3) Review the skill's disclaimers and ensure you understand its advisory role — its suggestions should be combined with rational business analysis for important decisions.

Review Dimensions

Purpose & Capability
okName, description, and SKILL.md consistently describe a 周易/风水/命名/择日 advisor for business decisions. The information the skill collects (name, birth date, event type, participants' zodiac, time range) is appropriate and expected for the stated functionality.
Instruction Scope
okSKILL.md contains only role instructions, analysis frameworks, templates, and prompts for collecting user-supplied background (e.g., name, birthdate, event). It does not instruct the agent to read local files, access system environment variables, contact external endpoints, or exfiltrate data.
Install Mechanism
okNo install spec and no code files — instruction-only. Nothing is written to disk or downloaded during install, which is proportionate for a pure guidance/role skill.
Credentials
okThe skill declares no required environment variables, credentials, or config paths. The only sensitive inputs are personal data requested from users (name, birthdate), which are justified by the domain (natal data needed for readings).
Persistence & Privilege
okalways:false (no forced global inclusion). disable-model-invocation is false (the agent may invoke the skill autonomously), which is the platform default — not flagged on its own. The skill does not request modification of other skills or system settings.