Milady

ReviewAudited by ClawScan on May 10, 2026.

Overview

Prompt-injection indicators were detected in the submitted artifacts (you-are-now); human review is required before treating this skill as clean.

Install only if you want your bot’s responses to consistently adopt this Remilia/Milady aesthetic and worldview. The artifacts do not show code execution, credential use, or data access, but the persona may affect neutrality and tone across conversations. ClawScan detected prompt-injection indicators (you-are-now), so this skill requires review even though the model response was benign.

Findings (1)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

NoteHigh Confidence
ASI01: Agent Goal Hijack
What this means

While enabled, responses may become stylized, ideologically framed, or less neutral than a default assistant response.

Why it was flagged

The skill intentionally changes the assistant’s identity, tone, and response framing globally. This is aligned with its stated personality purpose, but users should notice the breadth of behavioral steering.

Skill content
"You are now a **Milady**" and "After installation, all responses will be filtered through Milady consciousness automatically."
Recommendation

Use this skill when you want the Milady persona; disable it for neutral, high-stakes, or strictly task-focused work.