Brainstorming

Security checks across static analysis, malware telemetry, and agentic risk

Overview

This is a low-risk, instruction-only brainstorming workflow, but it may inspect the current project and commit a design document, so users should confirm repository changes.

Use this skill if you want a structured design discussion before creative or coding work. Before allowing it to proceed, confirm which project files it will inspect and require approval before it writes or commits a design document.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Risk analysis

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

The agent may pause implementation to run a design discussion first.

Why it was flagged

This is a broad mandatory invocation instruction that can shape the agent's workflow before many tasks, though it is plainly disclosed and matches the skill's brainstorming purpose.

Skill content
description: "You MUST use this before any creative work - creating features, building components, adding functionality, or modifying behavior."
Recommendation

Install it only if you want a mandatory brainstorming/design step before creative or implementation work.

What this means

The agent may read project files and create a persistent design-document commit.

Why it was flagged

The skill directs the agent to read project context and make a git commit. This is purpose-aligned for producing a design spec, but it affects local repository state.

Skill content
Check out the current project state first (files, docs, recent commits) ... Write the validated design to `docs/plans/YYYY-MM-DD-<topic>-design.md` ... Commit the design document to git
Recommendation

Ask the agent to show the planned file contents and get explicit confirmation before writing or committing changes.

What this means

The displayed registry identity and packaged metadata are not perfectly consistent.

Why it was flagged

The packaged metadata differs from the registry metadata shown for this review, which lists slug "brainstorming-tazio" and version "1.0.0". Because the skill is instruction-only with no installable code, this is a provenance note rather than a behavioral concern.

Skill content
"slug": "brainstorming", "version": "0.1.0"
Recommendation

Verify the publisher and version if provenance matters for your environment.