Back to skill
Skillv1.0.0

ClawScan security

深度认知能力构建系统 · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 29, 2026, 4:12 AM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
This is an instruction-only skill (a mindset/learning guide) whose requirements and instructions match its stated purpose and ask for no credentials or installs.
Guidance
This skill is essentially a written curriculum and appears coherent and low-risk: it doesn't ask for keys or install code. Before use, confirm you trust the (unknown) publisher because provenance is not provided. If you follow its tooling suggestions (Notion, Neo4j, GPT-4, etc.), be careful when connecting those services — they will require credentials and may expose your notes/data. Never paste secrets or private data into prompts or external tools when testing the exercises. If you need the agent to actually integrate with any listed tool, require an explicit integration step and review what credentials are requested at that time.

Review Dimensions

Purpose & Capability
okThe skill is a prose-based curriculum for building 'deep cognition' (training steps, frameworks, and book recommendations). It declares no binaries, env vars, config paths, or installs — which is proportionate to its teaching/documentation purpose.
Instruction Scope
noteSKILL.md is a self-contained guide and does not include runtime commands, file reads, or credential access. It mentions external tools/services (Notion, Neo4j, XMind, GPT-4/Codex/Rasa) as suggested tooling but does not instruct the agent to call APIs or access secrets. Note: those mentions imply optional integrations that would require separate credentials if the user chooses to follow them.
Install Mechanism
okNo install spec and no code files — nothing is written to disk or fetched during install. This is the lowest-risk installation profile.
Credentials
okThe skill requests no environment variables, keys, or credentials. Mentions of third-party services are purely advisory and do not create hidden credential demands.
Persistence & Privilege
okalways is false and the skill does not request persistent or elevated privileges, nor does it indicate modifying other skills or system settings.