Back to skill
Skillv1.0.0
ClawScan security
Call Reluctance Diagnostic · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignApr 17, 2026, 5:14 AM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- This instruction-only coaching skill is internally consistent with its stated purpose (diagnosing call reluctance and producing a 1-week intervention) and requests no credentials or installs.
- Guidance
- This skill appears coherent and low-risk: it only needs a user's self-report and activity numbers to produce a diagnosis and plan. Before using it, avoid pasting or uploading sensitive or customer-identifying data (customer PII, lead lists, contract details) into the input document, since that content will be read and processed by the skill. Note the skill draws on copyrighted material (Fanatical Prospecting); if you plan to redistribute outputs, verify licensing. If the skill is later updated to include installs, network endpoints, or required environment variables, re-evaluate before enabling it. If you want extra assurance, test it with anonymized sample data first.
Review Dimensions
- Purpose & Capability
- okName, description, and tasks (diagnose prospecting blockers, run a seven-mindsets baseline, apply the Three Ps, produce a 1-week plan) match the SKILL.md and included reference files. There are no unexpected environment variables, binaries, or config paths requested that would be unrelated to a coaching/diagnostic function.
- Instruction Scope
- okRuntime instructions are limited to reading the user's self-report, collecting recent activity counts, scoring mindset rubrics, scanning language for victim-mindset markers, and producing a written plan. The instructions do not direct the agent to read system files, access credentials, or send data to external endpoints. The skill expects a user-provided document as input, which is appropriate for the task.
- Install Mechanism
- okThere is no install specification and no code files — this is an instruction-only skill. That is the lowest-risk model (nothing is written to disk or fetched at install time).
- Credentials
- okThe skill declares no required environment variables, credentials, or config paths. It only asks for user-provided behavioral and activity data (which is proportional to a coaching diagnostic).
- Persistence & Privilege
- okalways:false and default invocation settings. The skill does not request persistent presence or modify system/other-skill settings. Autonomous invocation is allowed by platform default but the skill's scope is narrow.
