Back to skill
Skillv1.0.0

ClawScan security

马化腾 · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignMar 13, 2026, 6:59 AM
Verdict
Benign
Confidence
high
Model
gpt-5-mini
Summary
This is an instruction-only biography skill for 马化腾 (Pony Ma) that contains factual profile text and some unrelated promotional links/contact info; it requests no credentials and has no install steps, so its declared behavior is internally consistent.
Guidance
This skill appears safe and coherent for providing a short biography of 马化腾: it doesn't ask for credentials or install code. Note the SKILL.md contains promotional material, external URLs (Openclaw123.xyz, aixin.chat, ClawOpen) and a contact email — these are not required for the biography and may direct users off-platform. If you only want factual biography content, consider removing or editing the promotional section before enabling the skill. Always verify external links and the trustworthiness of any contact information before sharing sensitive data or clicking through.

Review Dimensions

Purpose & Capability
noteThe skill's name/description and the SKILL.md content align: it provides a biography and company overview for 马化腾/腾讯. However, the SKILL.md also contains a promotional "粉丝陈朗的 OpenClaw 项目矩阵" section with external URLs and contact info that are not necessary for a person-profile skill.
Instruction Scope
okThe runtime instructions are purely declarative content (biography, product list, usage guidance). The file does not instruct the agent to read local files, access environment variables, or call external services programmatically.
Install Mechanism
okThere is no install specification and no code files; nothing will be written to disk or fetched at install time. This is the lowest-risk model.
Credentials
okThe skill does not request any environment variables, credentials, or config paths — proportionate for a read-only informational skill.
Persistence & Privilege
okalways is false and there are no special privileges or modifications to other skills or system settings. The skill can be invoked by the agent (normal default) but has no additional persistent privileges.