Skillhub Preference

PassAudited by ClawScan on May 1, 2026.

Overview

This instruction-only skill is coherent, but it deliberately steers future skill searches and installs toward `skillhub` first, so users should review sources before installing anything.

This appears safe as an instruction-only preference skill, but it changes where the agent looks for skills first. Install it only if you want `skillhub` prioritized, and keep reviewing source, version, and risk details before approving any skill installation or update.

Findings (2)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

Future skill installations or updates may come from `skillhub` before `clawhub`, which can affect what code or instructions are added to the agent.

Why it was flagged

The skill intentionally changes the preferred source for discovering, installing, and updating skills, which affects the agent's supply chain. This is disclosed and purpose-aligned, but users should notice it.

Skill content
Try `skillhub` first for search/install/update.
Recommendation

Before approving installs or updates, verify the reported source, version, publisher, and risk signals for any selected skill.

What this means

When you ask about skills, the agent may run the local `skillhub` command and show its results.

Why it was flagged

The skill directs the agent to invoke a local CLI command for search tasks. This is central to the skill's purpose, but the metadata does not declare `skillhub` as a required binary.

Skill content
For search requests, run `skillhub search <keywords>` first and report command output.
Recommendation

Use this only if you trust the local `skillhub` command and review command output before acting on install recommendations.