Back to skill
Skillv1.0.0
ClawScan security
Aunkar Social Draft · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignMar 3, 2026, 5:25 AM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- The skill is an instruction-only drafting helper for Twitter/X and LinkedIn and its requested resources and behavior are consistent with that purpose.
- Guidance
- This skill is instruction-only and appears to only generate draft text for X (Twitter) and LinkedIn — it does not post for you and does not request credentials. Before installing or using it, consider: (1) review any generated content before posting (to avoid accidental PII or inaccurate claims), (2) confirm it matches the current platform rules and character limits (platform names/limits can change), and (3) if you later extend it to perform posting, require explicit credentials and review network/call behavior carefully.
Review Dimensions
- Purpose & Capability
- okThe name and description (draft Twitter/LinkedIn posts) match the SKILL.md instructions. The skill does not request unrelated binaries, credentials, or config paths.
- Instruction Scope
- okRuntime instructions are limited to asking the user for context and producing platform-optimized drafts; they do not instruct reading files, accessing environment variables, or sending data to external endpoints.
- Install Mechanism
- okNo install spec or code is included (instruction-only), so nothing is written to disk or downloaded during install.
- Credentials
- okNo environment variables, credentials, or config paths are required. This is proportionate for a drafting-only skill that doesn't actually post on behalf of the user.
- Persistence & Privilege
- okThe skill is not marked always:true and does not request elevated persistence or modification of other skills' configs. It can be invoked by the user or autonomously per platform defaults.
