Back to skill
Skillv1.0.0

ClawScan security

Aunkar Social Draft · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignMar 3, 2026, 5:25 AM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
The skill is an instruction-only drafting helper for Twitter/X and LinkedIn and its requested resources and behavior are consistent with that purpose.
Guidance
This skill is instruction-only and appears to only generate draft text for X (Twitter) and LinkedIn — it does not post for you and does not request credentials. Before installing or using it, consider: (1) review any generated content before posting (to avoid accidental PII or inaccurate claims), (2) confirm it matches the current platform rules and character limits (platform names/limits can change), and (3) if you later extend it to perform posting, require explicit credentials and review network/call behavior carefully.

Review Dimensions

Purpose & Capability
okThe name and description (draft Twitter/LinkedIn posts) match the SKILL.md instructions. The skill does not request unrelated binaries, credentials, or config paths.
Instruction Scope
okRuntime instructions are limited to asking the user for context and producing platform-optimized drafts; they do not instruct reading files, accessing environment variables, or sending data to external endpoints.
Install Mechanism
okNo install spec or code is included (instruction-only), so nothing is written to disk or downloaded during install.
Credentials
okNo environment variables, credentials, or config paths are required. This is proportionate for a drafting-only skill that doesn't actually post on behalf of the user.
Persistence & Privilege
okThe skill is not marked always:true and does not request elevated persistence or modification of other skills' configs. It can be invoked by the user or autonomously per platform defaults.