Skillhub Preference
PassAudited by ClawScan on May 1, 2026.
Overview
This instruction-only skill is coherent, but it deliberately steers future skill searches and installs toward `skillhub` first, so users should review sources before installing anything.
This appears safe as an instruction-only preference skill, but it changes where the agent looks for skills first. Install it only if you want `skillhub` prioritized, and keep reviewing source, version, and risk details before approving any skill installation or update.
Findings (2)
Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.
Future skill installations or updates may come from `skillhub` before `clawhub`, which can affect what code or instructions are added to the agent.
The skill intentionally changes the preferred source for discovering, installing, and updating skills, which affects the agent's supply chain. This is disclosed and purpose-aligned, but users should notice it.
Try `skillhub` first for search/install/update.
Before approving installs or updates, verify the reported source, version, publisher, and risk signals for any selected skill.
When you ask about skills, the agent may run the local `skillhub` command and show its results.
The skill directs the agent to invoke a local CLI command for search tasks. This is central to the skill's purpose, but the metadata does not declare `skillhub` as a required binary.
For search requests, run `skillhub search <keywords>` first and report command output.
Use this only if you trust the local `skillhub` command and review command output before acting on install recommendations.
