Back to skill
Skillv1.0.0
ClawScan security
xuanxuan-10agents · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignApr 25, 2026, 4:03 AM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- The skill is an instruction-only role for providing traditional Chinese 'Yijing' / feng shui style advice; its requested inputs and behaviors match that purpose and it doesn't ask for unrelated system access or credentials.
- Guidance
- This skill appears internally consistent for providing traditional Yijing/feng shui style advice. Before installing: 1) Be aware it will prompt for personal data (name, birthdate, participant zodiacs); only share what you are comfortable providing and avoid highly sensitive identifiers (national ID numbers, full addresses, payment info). 2) The skill is instruction-only and makes no external calls or credential requests according to the provided files, but confirm runtime platform rules (e.g., whether agents log or transmit conversation history externally) if you have privacy concerns. 3) Review the skill's disclaimers and ensure you understand its advisory role — its suggestions should be combined with rational business analysis for important decisions.
Review Dimensions
- Purpose & Capability
- okName, description, and SKILL.md consistently describe a 周易/风水/命名/择日 advisor for business decisions. The information the skill collects (name, birth date, event type, participants' zodiac, time range) is appropriate and expected for the stated functionality.
- Instruction Scope
- okSKILL.md contains only role instructions, analysis frameworks, templates, and prompts for collecting user-supplied background (e.g., name, birthdate, event). It does not instruct the agent to read local files, access system environment variables, contact external endpoints, or exfiltrate data.
- Install Mechanism
- okNo install spec and no code files — instruction-only. Nothing is written to disk or downloaded during install, which is proportionate for a pure guidance/role skill.
- Credentials
- okThe skill declares no required environment variables, credentials, or config paths. The only sensitive inputs are personal data requested from users (name, birthdate), which are justified by the domain (natal data needed for readings).
- Persistence & Privilege
- okalways:false (no forced global inclusion). disable-model-invocation is false (the agent may invoke the skill autonomously), which is the platform default — not flagged on its own. The skill does not request modification of other skills or system settings.
