Back to skill
v1.0.0
Review Monitoring
BenignClawScan verdict for this skill. Analyzed May 1, 2026, 8:23 AM.
Analysis
This is a coherent instruction-only skill for e-commerce review monitoring, with the main thing to verify being its documented external install command.
GuidanceThis skill appears safe as an instruction-only guide. Before installing via the documented npx command, confirm that the Nexscope/GitHub source is the one you intend to trust.
Findings (1)
Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.
Abnormal behavior control
Checks for instructions or behavior that redirect the agent, misuse tools, execute unexpected code, cascade across systems, exploit user trust, or continue outside the intended task.
Agentic Supply Chain Vulnerabilities
SeverityLowConfidenceHighStatusNote
SKILL.md
npx skills add nexscope-ai/eCommerce-Skills --skill review-monitoring -g
This is a user-directed install command that references an external repository-style source and global installation; it is relevant to provenance, even though it is not automatic runtime behavior.
User impactIf copied and run, the command may install a skill bundle globally from an external source.
RecommendationVerify the publisher and repository before running the command, and prefer trusted registry or reviewed installation paths where available.
