Back to skill
Skillv1.0.1

ClawScan security

VC 论坛精华帖整理 · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignMar 13, 2026, 8:08 AM
Verdict
Benign
Confidence
high
Model
gpt-5-mini
Summary
This skill is a read-only curated collection of Visual Components forum posts and code examples; it requests no credentials, installs nothing, and the content matches the stated purpose.
Guidance
This skill is a read-only curated reference of forum threads and code snippets and appears coherent with its description. Before using: (1) verify and inspect any downloadable attachments (e.g., the .zip) in a safe environment before running code or installing plugins, (2) review and test forum-provided scripts in a sandboxed VC model or separate environment, and (3) confirm compatibility with your Visual Components version (some posts note version constraints). No credentials are required by the skill itself.

Review Dimensions

Purpose & Capability
okName/description claim a curated collection of Visual Components forum threads; the skill is instruction-only and only contains links, excerpts, and example snippets — nothing unrelated is requested or required.
Instruction Scope
noteSKILL.md provides excerpts, links, and code samples from forum posts but does not instruct the agent to access local files, environment variables, or external endpoints beyond the referenced forum links. Note: it includes download links (a forum-hosted .zip attachment); the skill does not automatically download or execute them, but users should exercise caution before fetching or running attachments.
Install Mechanism
okNo install spec and no code files — lowest-risk instruction-only skill. Nothing is written to disk by the skill itself.
Credentials
okThe skill declares no required environment variables, credentials, or config paths. No unexplained secret access is requested.
Persistence & Privilege
okDefaults are used (not always:true). The skill is user-invocable and can be autonomously invoked by the agent per platform defaults, which is expected for skills; it does not request elevated or persistent privileges.