Back to skill
Skillv1.0.0

ClawScan security

language-polisher · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignMar 10, 2026, 6:01 AM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
The skill is an instruction-only text-polishing helper with no installs, no required credentials, and instructions that match its stated purpose.
Guidance
This skill appears coherent and low-risk, but remember it will process whatever text you give it — avoid submitting secrets or sensitive personal data. The SKILL.md asks the agent to explain why edits were made, so explanations may restate or summarize input; if you don't want that, instruct the agent not to include explanations. Because the skill is instruction-only and requests no credentials, the main concern is privacy of the text you provide rather than hidden functionality.

Review Dimensions

Purpose & Capability
okName and description (polishing, grammar, rewriting) align with the SKILL.md instructions. The skill declares no binaries, env vars, or config paths — all consistent with a lightweight text-editing helper.
Instruction Scope
noteSKILL.md stays focused on rewriting text, preserving meaning, and producing 1–2 alternatives. It also asks to 'Explain why you made such changes' which is reasonable for a polisher but will produce additional explanatory text (may restate or summarize user content). The instructions do not request reading files, env vars, or sending data to other endpoints.
Install Mechanism
okNo install spec and no code files — this is instruction-only, so nothing is written to disk or downloaded during install.
Credentials
okNo environment variables, credentials, or config paths are required; requested capabilities are minimal and proportional to a text-polishing task.
Persistence & Privilege
okalways is false and the skill does not request persistent or system-wide changes. It does not modify other skills or global agent settings.