Back to skill
Skillv1.0.0
ClawScan security
deep-night-treehole-1.0.0 · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignMar 11, 2026, 4:55 PM
- Verdict
- Benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- The skill is an instruction-only, empathy-focused companion whose requested resources and instructions match its stated purpose and do not request unrelated credentials, installs, or system access.
- Guidance
- This skill is internally coherent and low-risk from a resource/credential perspective: it is instruction-only, asks for no secrets, and stays within conversational scope. Before installing, consider: (1) it may prompt users to share sensitive personal thoughts — review your logging/privacy settings because conversation content could be stored by the agent platform; (2) it's not a substitute for professional mental health care — ensure the skill's responses include guidance toward professional help if serious issues arise; (3) if you want extra assurance, inspect the SKILL.md yourself (already included) and keep the skill disabled for autonomous invocation if you prefer manual control. Overall, it appears to do what it says.
Review Dimensions
- Purpose & Capability
- okName and description describe an empathetic companion. The skill requires no binaries, no credentials, and no config paths; SKILL.md contains only behavior rules and example dialogues in Chinese that align with that purpose.
- Instruction Scope
- okRuntime instructions limit behavior to empathetic listening, validation, and gentle optional organization. They do not instruct reading files, accessing environment variables, or contacting external endpoints. The allowed tool is AskUserQuestion, which is consistent with a conversational follow-up behavior.
- Install Mechanism
- okNo install spec and no code files — instruction-only — so nothing is written to disk and no external packages or downloads are required.
- Credentials
- okThe skill requests no environment variables, no credentials, and no config paths. Nothing disproportionate is requested for an emotional-companion skill.
- Persistence & Privilege
- okFlags are default (always: false). The skill does not request permanent/system-level presence or modify other skills' config. Autonomous invocation is allowed by default but is not a special privilege here.
