Back to skill
Skillv1.0.0
ClawScan security
Zengming · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignMar 3, 2026, 10:28 AM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- This is a read-only, instruction-only knowledge assistant about Professor Zeng Ming; it requires no credentials, no installs, and its instructions are limited to returning content from the bundled knowledge base.
- Guidance
- This skill appears low-risk and internally consistent: it is a static knowledge assistant about Professor Zeng Ming that asks for no secrets and installs nothing. Before installing, consider: 1) the content seems drawn from public sources but may be incomplete or outdated — verify important quotes and claims against primary sources; 2) this skill provides general commentary, not professional/legal/financial advice; 3) if you need up-to-date statements or full transcripts, confirm how the skill will be updated (it currently looks static). If those limitations are acceptable, the skill is reasonable to install.
Review Dimensions
- Purpose & Capability
- okName/description (a persona/knowledge assistant for 曾鸣) match the skill contents: the SKILL.md contains the knowledge snippets, use cases, and query patterns. There are no unrelated env vars, binaries, or config paths requested.
- Instruction Scope
- okRuntime instructions are simple and scoped: extract and present entries from the included knowledge base (core points, quotes, summaries). The SKILL.md does not instruct reading arbitrary files, accessing external endpoints, or collecting credentials. Note: the knowledge is static and based on public material; the skill does not declare dynamic update behavior.
- Install Mechanism
- okNo install spec and no code files (instruction-only). This minimizes disk/network risk — nothing is downloaded or installed at runtime.
- Credentials
- okThe skill requests no environment variables, credentials, or config paths; this is proportionate for a read-only knowledge assistant.
- Persistence & Privilege
- okalways is false and there are no special persistence requirements. The default ability for the agent to invoke the skill autonomously is unchanged — normal for skills and not alarming here.
