Back to skill
Skillv1.0.0
ClawScan security
Doc Coauthoring Anthropic · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignMar 14, 2026, 2:31 PM
- Verdict
- Benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- The instructions align with a co‑authoring workflow, the skill is instruction‑only (no install or credentials), and it only asks to read documents or platform connectors when the user enables them.
- Guidance
- This skill appears coherent and low‑risk: it only provides a writing workflow and asks to read documents or platform connectors if you enable them. Before using it, confirm which connectors (Google Drive, Slack, Teams, etc.) the platform will access and avoid pasting secrets or private credentials into the chat. If you prefer, keep connectors disabled and paste only the specific document text you want the assistant to read. If you need a deeper review (e.g., which platform connectors this skill will actually call), ask the publisher or platform for details about connector access and consent prompts.
Review Dimensions
- Purpose & Capability
- okThe name/description match the SKILL.md: it guides users through context gathering, iterative drafting, and reader testing. All stated actions (asking questions, drafting sections, reader testing) are coherent with a doc co‑authoring workflow.
- Instruction Scope
- noteInstructions ask the agent to read shared documents, team channels, and use platform integrations when available. That is expected for co‑authoring, but it means the agent may access potentially sensitive project content if the user enables connectors or pastes data — the skill does instruct to get user confirmation before searching connected tools.
- Install Mechanism
- okNo install spec and no code files — the skill is instruction‑only, so nothing is downloaded or written to disk by the skill itself.
- Credentials
- okThe skill declares no required environment variables, credentials, or config paths. Mentions of integrations rely on platform connectors rather than embedded credentials in the skill, which is proportionate to the described purpose.
- Persistence & Privilege
- okalways is false and the skill does not request persistent system privileges or modify other skills. Autonomous invocation is permitted (platform default) but not combined with other concerning privileges.
