Back to skill
Skillv1.0.1

ClawScan security

Atonement · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignMar 14, 2026, 12:44 AM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
This is an instruction-only, conceptual skill that provides philosophical guidance (the idea of “atonement”) and contains no code, installs, or requests for credentials — its declared behavior is internally consistent with its content.
Guidance
This skill is a piece of conceptual guidance, not executable code: it won't install software or ask for secrets. Before enabling it for important or safety-critical tasks, consider that its guidance is intentionally vague and 'non-legible' — it may cause the agent to behave in ways that are hard to audit or explain. If you require traceable, reviewable decision-making, avoid relying on this skill for autonomous or high-stakes actions. Otherwise it appears internally consistent and low-risk.

Review Dimensions

Purpose & Capability
okThe name and description match the SKILL.md content: this is a conceptual/philosophical behavioral guidance skill. It requests no binaries, env vars, or installs, which is appropriate for a purely instructional artifact.
Instruction Scope
noteThe SKILL.md is high-level and intentionally non-prescriptive/opaque (it describes non-legible, structural shifts in behaviour). It does not instruct the agent to read files, access credentials, or transmit data; however it is deliberately vague about how to implement or surface the behavior, which grants broad discretion to the agent. If you need auditable, explainable behavior, this vagueness is a relevant caveat.
Install Mechanism
okNo install spec and no code files are present. This is the lowest-risk class: nothing is written to disk or fetched during installation.
Credentials
okThe skill declares no environment variables, credentials, or config paths. There are no unexplained secrets or external-service requirements.
Persistence & Privilege
okalways is false and model invocation is allowed (the platform default). The skill does not request persistent system presence or modify other skills/configuration. No special privileges are requested.