Back to skill
Skillv1.0.0

ClawScan security

Scannable Reports · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignFeb 27, 2026, 8:01 PM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
The skill is an instruction-only formatting guide for chat-friendly text output and requests no credentials, installs, or system access — its declared purpose matches its content.
Guidance
This skill appears low-risk: it only provides text-formatting guidance for chat apps and does not install code or request secrets. Things to consider before installing: (1) provenance is unknown (no homepage/author page) — if you require third-party provenance, seek an authored source; (2) emoji/monospace rendering varies by platform and device, so test examples on your target apps; (3) autonomous invocation is allowed by default on the platform (normal), so if you want to restrict the agent from auto-applying formatting, disable or limit skill invocation in your agent policies.

Review Dimensions

Purpose & Capability
okName and description (mobile chat formatting: progress bars, sparklines, status indicators) align with the SKILL.md content. The skill does not ask for unrelated permissions or resources.
Instruction Scope
okSKILL.md contains only formatting rules, examples, and platform notes. It does not instruct the agent to read files, access environment variables, call external endpoints, or perform actions outside producing formatted text.
Install Mechanism
okNo install spec and no code files — nothing is downloaded or written to disk. This is the lowest-risk model (instruction-only).
Credentials
okThe skill declares no required environment variables, credentials, or config paths. There are no suspicious or excessive secret requests.
Persistence & Privilege
okFlags are default (not always:true). The skill does not request permanent presence or attempt to modify other skills or system config.