Back to skill
Skillv1.0.0
ClawScan security
Social Listening Report · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignApr 30, 2026, 4:56 AM
- Verdict
- Benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- Instruction-only skill that provides templates and question flows for producing social listening and benchmarking reports; its declared requirements and instructions are consistent with that purpose.
- Guidance
- This is an instruction-only skill that provides report templates and question flows — it does not fetch data from external services by itself and does not request API keys or environment secrets. Before installing or using it: 1) If you plan to paste real social data, scrub any personal data or credentials from exports; 2) if you expect automatic pulls from services (Talkwalker, Brandwatch, Google Analytics, etc.), be aware the skill does not include code or ask for API credentials — you would need a separate integration that would require keys; 3) watch for frequent/autonomous invocation because the trigger list is broad (the skill may be suggested whenever phrasing matches); and 4) validate any recommendations the skill generates against your raw data and domain knowledge to catch errors or hallucinations.
Review Dimensions
- Purpose & Capability
- noteName/description match the SKILL.md content (report templates, modules, and question flows). The skill lists many platforms (Talkwalker, Brandwatch, GA, SimilarWeb) but does not request API keys or binaries — that is consistent with a manual-data workflow, but if a user expects the skill to fetch data automatically it would need credentials which the skill does not request.
- Instruction Scope
- okSKILL.md confines the agent to asking the user for available data and producing structured reports; it does not instruct the agent to read local files, environment variables, or contact unexpected external endpoints. Triggers are broad (many phrase matches) which may increase how often the skill is invoked, but the instructions themselves stay on-scope.
- Install Mechanism
- okNo install spec and no code files — instruction-only skill. Nothing is written to disk and there is no third-party download or package installation.
- Credentials
- noteThe skill requests no environment variables or credentials (proportionate for a manual-data report generator). If you want automatic platform integrations, the skill would need API keys/credentials — the SKILL.md does not ask for them, so expect manual uploads or exports rather than autonomous API access.
- Persistence & Privilege
- okalways is false and there is no persistent install behavior or modification of other skills. disable-model-invocation is false (normal), so the agent can invoke this skill autonomously; combined with broad trigger phrases this may increase invocation frequency, but that is an expected operational detail rather than a misalignment.
