Back to skill
Skillv0.0.10

ClawScan security

Giggle Generation Scripts · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignMar 16, 2026, 2:38 AM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
This is an instruction-only script-writing skill whose requested resources and runtime instructions align with its stated purpose and do not ask for credentials, external installs, or unexpected system access.
Guidance
This skill is instruction-only and internally consistent with its stated purpose: it formats and constrains generated Chinese scripts in a specific stylistic manner and does not request credentials or install code. Consider these points before enabling it: (1) content/style: it aims to approximate a living filmmaker's style — while the SKILL.md states it won't copy specific film lines, generated text could still echo the flavor of real works, which may raise copyright or taste concerns depending on your usage; (2) moderation: the style guidelines include dark themes, violence, and black humor — review outputs for content you don't want published; (3) interaction model: scene scripts are intentionally serialized and require explicit user confirmation to continue, which can affect automated workflows (the agent will pause for confirmation per scene); (4) absence of scan findings is expected for an instruction-only skill but not a guarantee of safety — monitor initial outputs and revoke the skill if it behaves unexpectedly.

Review Dimensions

Purpose & Capability
okName/description (generate Chinese scripts in a Jiang Wen‑like style) match the content of SKILL.md and the included examples. The skill does not request unrelated binaries, credentials, or config paths.
Instruction Scope
okSKILL.md contains detailed, narrow instructions for collecting user inputs, formatting outputs, and an interactive serial scene protocol. It does not instruct the agent to read files outside the skill bundle, access environment variables, call external endpoints, or exfiltrate data. The only local file it references (references/examples.md) is provided in the bundle.
Install Mechanism
okNo install spec and no code files — instruction-only. Nothing will be downloaded or written to disk as part of an install step.
Credentials
okNo environment variables, credentials, or config paths are required. The scope of requested access is minimal and appropriate for a text-generation formatting skill.
Persistence & Privilege
okalways is false and model invocation is allowed (the platform default). The skill does not request permanent presence or elevated privileges, nor does it modify other skills or system-wide settings.