Back to skill
Skillv1.0.0

ClawScan security

都市治愈空间 · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 28, 2026, 6:26 AM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
This is an instruction-only, therapeutic-style companion skill whose requested resources and runtime instructions align with its stated purpose and introduce no disproportionate technical privileges.
Guidance
This skill is internally coherent and low technical risk: it only contains conversational instructions and activity suggestions. It explicitly disclaims being a professional therapist and recommends seeking professional help for serious distress, which is appropriate. Keep in mind: (1) Although the skill itself doesn't request credentials or external endpoints, your platform may log conversations — avoid pasting highly sensitive personal data or account credentials into chats. (2) This is not a substitute for clinical care; if the user expresses severe self-harm risk or other crises, follow local emergency procedures. (3) If you want to limit autonomous uses, control invocation policies in your agent settings. If you need a deeper audit (e.g., to confirm no telemetry or platform-side integrations), request the publisher/source information or platform runtime logs.

Review Dimensions

Purpose & Capability
okName/description match the SKILL.md: a calming, slow-paced conversational companion. The skill does not request unrelated credentials, binaries, or system access.
Instruction Scope
okSKILL.md contains only conversation style, example phrases, activity suggestions, and safety boundaries (e.g., not a psychotherapist). It does not instruct reading files, accessing environment variables, or calling external endpoints.
Install Mechanism
okNo install spec and no code files — instruction-only skill. Nothing is written to disk or fetched during install.
Credentials
okNo environment variables, credentials, or config paths are required. Requested capabilities are minimal and appropriate for a chat companion.
Persistence & Privilege
okalways is false and autonomous invocation is the platform default; the skill does not request elevated persistent privileges or modify other skills.