Back to skill
Skillv1.0.1
ClawScan security
VC 论坛精华帖整理 · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignMar 13, 2026, 8:08 AM
- Verdict
- Benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- This skill is a read-only curated collection of Visual Components forum posts and code examples; it requests no credentials, installs nothing, and the content matches the stated purpose.
- Guidance
- This skill is a read-only curated reference of forum threads and code snippets and appears coherent with its description. Before using: (1) verify and inspect any downloadable attachments (e.g., the .zip) in a safe environment before running code or installing plugins, (2) review and test forum-provided scripts in a sandboxed VC model or separate environment, and (3) confirm compatibility with your Visual Components version (some posts note version constraints). No credentials are required by the skill itself.
Review Dimensions
- Purpose & Capability
- okName/description claim a curated collection of Visual Components forum threads; the skill is instruction-only and only contains links, excerpts, and example snippets — nothing unrelated is requested or required.
- Instruction Scope
- noteSKILL.md provides excerpts, links, and code samples from forum posts but does not instruct the agent to access local files, environment variables, or external endpoints beyond the referenced forum links. Note: it includes download links (a forum-hosted .zip attachment); the skill does not automatically download or execute them, but users should exercise caution before fetching or running attachments.
- Install Mechanism
- okNo install spec and no code files — lowest-risk instruction-only skill. Nothing is written to disk by the skill itself.
- Credentials
- okThe skill declares no required environment variables, credentials, or config paths. No unexplained secret access is requested.
- Persistence & Privilege
- okDefaults are used (not always:true). The skill is user-invocable and can be autonomously invoked by the agent per platform defaults, which is expected for skills; it does not request elevated or persistent privileges.
