Back to skill
Skillv1.0.0

ClawScan security

China Classics中国古经典 · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 20, 2026, 11:33 AM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
An instruction-only reference skill that bundles curated text about Chinese classics; its declared requirements and runtime instructions align with that purpose and it requests no extra access or installs.
Guidance
This skill is internally coherent and low-risk technically: it only bundles reference text and asks for no credentials or installs. Before installing, consider non-technical factors: the source/homepage are unknown (limited provenance), the content may contain editorial choices or simplified/translated interpretations, and for scholarly or publication use you should verify citations against primary editions. If you need high-assurance academic references, cross-check with authoritative editions or databases (CTEXT, Zhonghua shu ju, etc.). Otherwise, it is safe from a credential/exfiltration perspective.

Review Dimensions

Purpose & Capability
okThe skill name/description (中国古经典知识库) match the provided files and SKILL.md: all content is reference material about classical Chinese texts. There are no unexpected environment variables, binaries, or install steps requested that would be disproportionate to a reference/lookup skill. (Note: source/homepage are unknown, which affects provenance but not technical coherence.)
Instruction Scope
okSKILL.md contains clear, scoped instructions: use the bundled reference content to answer queries about works, quotations, authors, editions, and reading guidance. It does not instruct the agent to read unrelated system files, access external endpoints, or exfiltrate data. All referenced material appears to be the included markdown files.
Install Mechanism
okThere is no install spec and no code files — the skill is instruction-only. This is the lowest-risk install model: nothing is downloaded or written to disk by the skill itself.
Credentials
okThe skill declares no required environment variables, credentials, or config paths and the runtime instructions do not reference any. The requested surface is minimal and proportionate to a read-only knowledge/reference skill.
Persistence & Privilege
okalways:false and standard autonomous invocation are used. The skill does not request permanent presence, system-level changes, or modification of other skills' configurations.