Back to skill
Skillv1.0.0
ClawScan security
Brw Linkedin Profile Optimizer 1.0.0 · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignFeb 23, 2026, 4:59 AM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- The skill's requested inputs, instructions, and absence of installs/credentials are consistent with a LinkedIn profile rewriting tool and do not request unrelated system access or secrets.
- Guidance
- This skill appears to do what it says: it asks you to paste LinkedIn copy and returns audits and rewrites. Before using it, do not paste credentials, private messages, health/financial identifiers, or other sensitive PII into the prompt — only paste the profile text you are comfortable sharing. You don't need to provide LinkedIn login details or API keys (and the skill does not request them). If you're concerned about privacy, redact personal contact details or replace them with placeholders before pasting, and review edits locally before updating your live LinkedIn profile.
Review Dimensions
- Purpose & Capability
- okName and description match the runtime instructions: the skill asks users to paste LinkedIn text and returns audits and rewrites. It does not request unrelated binaries, cloud credentials, or system access that would be disproportionate to this purpose.
- Instruction Scope
- noteThe SKILL.md only instructs the agent to ask the user for their profile text (headline, About, experience, etc.) and to produce rewritten output; it does not direct the agent to read files, environment variables, or send data to external endpoints. Note: the skill asks for full About and experience text (user-supplied content may contain personal or sensitive information), so users should avoid pasting passwords, private messages, or other secrets.
- Install Mechanism
- okInstruction-only skill with no install spec and no code files, so nothing is written to disk or downloaded during install — minimal installation risk.
- Credentials
- okThe skill declares no required environment variables, credentials, or config paths. There are no requests for unrelated API keys or secrets, which is appropriate for a copy/editing tool.
- Persistence & Privilege
- okalways is false (not force-included). disable-model-invocation is false, which is the platform default allowing the agent to call the skill autonomously; this is expected for an actionable skill and is not problematic here because the skill requests no extra privileges or credentials.
