Back to skill
Skillv1.0.0

ClawScan security

mar-content-writer · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 23, 2026, 3:57 AM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
Instruction-only content-generation skill whose declared purpose matches its instructions; no installs, credentials, or system access are requested.
Guidance
This skill appears to be what it claims: an instruction-only content writer for Chinese social platforms. Before installing, consider: 1) clarify how (or whether) it will call any external 'seo-optimizer' tool referenced in the checklist; don't grant access to other tools/credentials unless you trust them. 2) Review outputs for plagiarism, platform policy compliance, and legal/sensitive content before publishing. 3) Test generated posts on a staging account to confirm formatting and word-count norms. No environment or install risks were found in the provided files.

Review Dimensions

Purpose & Capability
okThe name/description (Chinese social-media content generator) align with the SKILL.md workflow and templates for 小红书, 知乎, 公众号, and 抖音. There are no unrelated requirements (no env vars, binaries, or install steps) that would be inconsistent with the stated purpose.
Instruction Scope
noteThe instructions are narrowly scoped to collecting content inputs and producing platform-native output formats and a checklist. One minor open-ended reference: the Quality Checklist suggests 'cross-check with seo-optimizer' but that tool is neither included nor declared; this grants implicit reliance on another skill or tool and should be clarified before assuming integration. Otherwise the SKILL.md does not instruct reading files, credentials, or system state.
Install Mechanism
okNo install spec and no code files—this is instruction-only, so nothing will be downloaded or written to disk. This is the lowest-risk install profile.
Credentials
okThe skill declares no required environment variables, credentials, or config paths. There are no requests for secrets or unrelated service tokens, which is proportional to a content-generation skill.
Persistence & Privilege
okalways is false and the skill does not request persistent/system-wide changes or elevated privileges. Autonomous invocation is allowed (platform default) but not combined with broad access in this skill.