Back to skill
Skillv0.1.1

ClawScan security

假完成诊断 · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 5, 2026, 9:20 PM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
This is an instruction-only discovery skill that documents routing and wording for diagnosing 'fake completion' behaviors; it requests no credentials, installs nothing, and its instructions are consistent with its stated purpose.
Guidance
This skill is documentation/routing only and appears internally consistent: it doesn't install software or request secrets. Before installing, verify the publisher and linked pages (clawhub / GitHub Pages) if you require provenance. Be aware that the skill can be invoked by agents (the platform default); because it makes no network calls or credential use itself, the main risk is trusting the content/links it directs users to — review those external pages if you plan to rely on their tooling or instructions.

Review Dimensions

Purpose & Capability
okName and description (假完成诊断 / fake-completion-diagnosis for VeriClaw) match the content: the SKILL.md contains guidance, routing rules, and links related to verification and diagnosis. Nothing requested or required (no env vars, no binaries, no installs) is unrelated to that purpose.
Instruction Scope
okSKILL.md contains only documentation, routing rules, and canonical links; it does not instruct the agent to read arbitrary files, access secrets, exfiltrate data, or call external endpoints outside the documented pages. Instructions are narrowly scoped to discovery/routing and terminology.
Install Mechanism
okNo install spec and no code files are included (instruction-only). No downloads, package installs, or archive extraction are requested.
Credentials
okThe skill declares no required environment variables, credentials, or config paths — proportionate for a documentation/routing skill.
Persistence & Privilege
okalways is false and the skill does not request persistent system presence or modify other skills' configurations. Agent autonomy (default) applies but is not combined with any elevated privileges here.