Back to skill
Skillv1.0.0
ClawScan security
Korean Daily Drill · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignMar 25, 2026, 7:16 AM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- The skill is instruction-only and self-consistent: it asks no credentials, installs nothing, and its runtime instructions align with its stated purpose of generating tailored Korean practice sessions.
- Guidance
- This skill appears coherent and low-risk: it simply instructs the agent to generate Korean practice content and requests no credentials or installs. Before enabling: (1) Decide whether you want the agent to store your level in OpenClaw memory (README suggests it as a convenience) — only enable that if you’re comfortable saving that preference. (2) As with any content-generation skill, review translations and examples for accuracy before relying on them for study or exams. (3) If you prefer to prevent autonomous invocation by agents, turn off model/autonomous invocation in your OpenClaw/agent settings; the skill itself does not require that setting.
Review Dimensions
- Purpose & Capability
- okName/description match the actual instructions. The skill generates vocabulary, grammar, Hangul/Hanja, reading, speaking prompts and quizzes and requests no unrelated binaries, credentials, or config paths.
- Instruction Scope
- noteSKILL.md stays within the language-teaching scope and does not instruct reading files, contacting external endpoints, or exfiltrating data. The README suggests storing the user's level in OpenClaw memory as an optional convenience — this is a user-configurable platform feature, not an automatic request by the skill.
- Install Mechanism
- okNo install spec and no code files — lowest-risk instruction-only skill. Nothing is downloaded or written to disk by the skill itself.
- Credentials
- okNo environment variables, credentials, or config paths are required. The skill does not request secrets or external API keys.
- Persistence & Privilege
- okalways:false and user-invocable:true. The skill does not request persistent system privileges or modify other skills. Note: the platform default allows autonomous invocation unless you disable it in agent settings; that is a platform-level policy rather than the skill requesting elevated persistence.
