Back to skill
Skillv1.0.0
ClawScan security
Creator Outreach · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignMar 12, 2026, 2:07 PM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- The skill is an instruction-only outreach helper whose requested resources and instructions match its stated purpose and do not ask for credentials, installs, or unrelated system access.
- Guidance
- This skill is instruction-only and appears low-risk. Before using it, avoid pasting sensitive personal data or private credentials (payment info, full contact lists, or secret metrics) into prompts. Be mindful that the agent may autonomously call the skill when applicable; review any generated outreach for accuracy (do not rely on invented metrics) and for privacy compliance before sending to creators.
Review Dimensions
- Purpose & Capability
- okName and description (creator outreach drafts, follow-ups, CTAs) align with the provided instructions; no unrelated binaries, credentials, or config paths are required.
- Instruction Scope
- okSKILL.md stays on-task: it defines a workflow, the minimal context to collect (creator name/handle, reason, product, next step, proof/budget/timing), drafting guidance, and an output template. It does not instruct the agent to read files, access system configs, or transmit data to external endpoints.
- Install Mechanism
- okNo install spec and no code files — instruction-only skill. This is the lowest-risk install surface (nothing written to disk or executed).
- Credentials
- okNo environment variables, credentials, or config paths are requested. The context fields requested are proportional to outreach drafting.
- Persistence & Privilege
- okSkill is not forced-always; it is user-invocable and can be called autonomously per platform defaults. It does not request persistent system presence or modify other skills.
