expert-mode
AdvisoryAudited by Static analysis on Apr 30, 2026.
Overview
No suspicious patterns detected.
Findings (0)
Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.
Approved expert entries may affect future assistant behavior until the memory entry is changed or removed.
The skill persists fetched expert data into agent memory and later uses that data to shape responses. This is expected for the feature, but persistent external context can influence future behavior if a bad update is approved.
用户确认后才执行写入 ... 更新MEMORY.md ... 调整自身响应风格以匹配该专家的角色定位
Review update previews carefully, keep expert entries limited to names and descriptions where possible, and remove unexpected MEMORY.md additions.
An outdated or altered mirror could change the expert list that is proposed for persistence.
The update workflow relies on several external repositories and possible mirrors. This is disclosed and purpose-aligned, but mirrored or unofficial sources can differ from the original upstream content.
4个仓库 ... GitHub镜像 - fastgit、ghproxy等国内镜像 ... Gitee镜像 - 搜索Gitee同步镜像
Prefer the official GitHub repositories, inspect the proposed changes before confirming, and avoid accepting updates from unknown mirrors.
If used, additional automation or sub-agents may participate in fetching update content.
The skill describes fallback fetching through browser automation and spawned sub-agents. This is tied to retrieving public expert-list updates, but it introduces delegated tool or agent activity users should notice.
浏览器自动化 - 浏览器可继承系统代理 ... 子代理抓取 - spawn子代理尝试不同网络
Use these fallback methods only when needed and avoid including sensitive task context in update-fetching prompts.
If enabled, the skill may periodically check for updates and ask to write them to memory.
The skill includes a scheduled auto-sync option. It is disabled by default and still requires confirmation before writing, so this is disclosed and bounded persistence rather than hidden background behavior.
Cron自动同步功能默认禁用 ... 需要用户主动开启 ... 开启后每次同步仍需确认
Leave auto-sync disabled unless you need it, and verify each proposed update before confirming.
