Back to skill
Skillv1.0.0
ClawScan security
Social Media Content Generator · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignApr 29, 2026, 10:52 PM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- The skill's instructions, requirements, and scope match its description: it's an instruction-only social media post generator that asks for source content and returns platform-formatted outputs, with no installs or credential requests.
- Guidance
- This skill is instruction-only and coherent with its description, so technical risk is low. Before installing, consider: (1) provenance — the source/homepage is unknown, so only enable it if you trust the publisher; (2) privacy — do not submit sensitive secrets, personal data, or proprietary IP as the source content; (3) platform compliance — review generated posts for brand/legal/policy compliance before posting; (4) autonomous use — the skill can be invoked by the agent when permitted by your agent settings, so ensure you only allow autonomous actions for skills you trust. If you need stronger guarantees, ask for a skill from a known publisher or one that documents data handling and provenance.
Review Dimensions
- Purpose & Capability
- okName/description promise (generate posts for X, LinkedIn, Instagram, Facebook) lines up with the SKILL.md templates and step-by-step generation workflow. There are no unrelated requirements (no binaries, no creds) requested that would contradict the stated purpose.
- Instruction Scope
- okSKILL.md instructs the agent to request source content, platform selection, tone, and audience, then produce platform-specific outputs and templates. It does not direct the agent to read system files, environment variables, or send data to external endpoints beyond returning generated content to the user.
- Install Mechanism
- okNo install spec and no code files — this is instruction-only. That minimizes on-disk execution and is proportionate for a text-generation helper.
- Credentials
- okThe skill requires no environment variables, credentials, or config paths. Requested inputs are user-provided content and preferences, which are appropriate for the task. (Note: user-provided content may itself contain sensitive data — see guidance.)
- Persistence & Privilege
- okalways is false and there is no install that would create persistent binaries or modify other skills. disable-model-invocation is false (agent may invoke autonomously by default) — this is platform-normal and not, by itself, a concern.
