Back to skill
Skillv1.0.0
ClawScan security
深度认知能力构建系统 · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignApr 29, 2026, 4:12 AM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- This is an instruction-only skill (a mindset/learning guide) whose requirements and instructions match its stated purpose and ask for no credentials or installs.
- Guidance
- This skill is essentially a written curriculum and appears coherent and low-risk: it doesn't ask for keys or install code. Before use, confirm you trust the (unknown) publisher because provenance is not provided. If you follow its tooling suggestions (Notion, Neo4j, GPT-4, etc.), be careful when connecting those services — they will require credentials and may expose your notes/data. Never paste secrets or private data into prompts or external tools when testing the exercises. If you need the agent to actually integrate with any listed tool, require an explicit integration step and review what credentials are requested at that time.
Review Dimensions
- Purpose & Capability
- okThe skill is a prose-based curriculum for building 'deep cognition' (training steps, frameworks, and book recommendations). It declares no binaries, env vars, config paths, or installs — which is proportionate to its teaching/documentation purpose.
- Instruction Scope
- noteSKILL.md is a self-contained guide and does not include runtime commands, file reads, or credential access. It mentions external tools/services (Notion, Neo4j, XMind, GPT-4/Codex/Rasa) as suggested tooling but does not instruct the agent to call APIs or access secrets. Note: those mentions imply optional integrations that would require separate credentials if the user chooses to follow them.
- Install Mechanism
- okNo install spec and no code files — nothing is written to disk or fetched during install. This is the lowest-risk installation profile.
- Credentials
- okThe skill requests no environment variables, keys, or credentials. Mentions of third-party services are purely advisory and do not create hidden credential demands.
- Persistence & Privilege
- okalways is false and the skill does not request persistent or elevated privileges, nor does it indicate modifying other skills or system settings.
