Back to skill
Skillv1.9.2
ClawScan security
Xue Feng Skill V192 · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignApr 17, 2026, 4:10 AM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- The skill is an instruction-only guidance framework for choosing Chinese college majors and career paths; its requirements and runtime instructions are consistent with that purpose and it does not request extra credentials or install code.
- Guidance
- This skill is a content/instruction bundle (no code, no installs, no credentials). Before enabling it: 1) understand it will ask for personal academic details (scores, province, gender, family resources) to give tailored advice—share only what you’re comfortable with; 2) it relies on live WebSearch for up-to-date employment, salary, and policy data, so verify the cited sources yourself when making real decisions; 3) the skill is an explicit imitation of public instructors—treat its recommendations as synthesized guidance, not an official professional or legal opinion; and 4) because it uses external web searches, monitor that the agent’s search tool returns reputable sources (government, university, or industry reports) before acting on numeric or policy claims.
Review Dimensions
- Purpose & Capability
- okThe name, description, and SKILL.md all describe a college-major / career-planning advisor. There are no required binaries, env vars, or config paths that are unrelated to this purpose.
- Instruction Scope
- noteThe instructions tell the agent to collect personal inputs (scores, province, gender, family situation, career preferences) and to always perform WebSearch to verify up-to-date employment, salary, and policy data before making concrete recommendations. That data collection and web search are appropriate for the stated purpose, but users should be aware the skill will ask for personal academic and family information (non-sensitive but personal) and rely on external web searches for current data.
- Install Mechanism
- okThis is instruction-only with no install spec and no code files, so nothing will be written to disk or installed at runtime.
- Credentials
- okThe skill declares no required environment variables, credentials, or config paths. The personal fields it asks the agent to collect from users are proportionate to making tailored major/career suggestions.
- Persistence & Privilege
- okalways is false and the skill does not request persistent system privileges or modify other skills or agent-wide configs. Autonomous invocation is allowed by default but not combined with other red flags.
