Back to skill
Skillv1.0.0

ClawScan security

Korean Daily Drill · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignMar 25, 2026, 7:16 AM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
The skill is instruction-only and self-consistent: it asks no credentials, installs nothing, and its runtime instructions align with its stated purpose of generating tailored Korean practice sessions.
Guidance
This skill appears coherent and low-risk: it simply instructs the agent to generate Korean practice content and requests no credentials or installs. Before enabling: (1) Decide whether you want the agent to store your level in OpenClaw memory (README suggests it as a convenience) — only enable that if you’re comfortable saving that preference. (2) As with any content-generation skill, review translations and examples for accuracy before relying on them for study or exams. (3) If you prefer to prevent autonomous invocation by agents, turn off model/autonomous invocation in your OpenClaw/agent settings; the skill itself does not require that setting.

Review Dimensions

Purpose & Capability
okName/description match the actual instructions. The skill generates vocabulary, grammar, Hangul/Hanja, reading, speaking prompts and quizzes and requests no unrelated binaries, credentials, or config paths.
Instruction Scope
noteSKILL.md stays within the language-teaching scope and does not instruct reading files, contacting external endpoints, or exfiltrating data. The README suggests storing the user's level in OpenClaw memory as an optional convenience — this is a user-configurable platform feature, not an automatic request by the skill.
Install Mechanism
okNo install spec and no code files — lowest-risk instruction-only skill. Nothing is downloaded or written to disk by the skill itself.
Credentials
okNo environment variables, credentials, or config paths are required. The skill does not request secrets or external API keys.
Persistence & Privilege
okalways:false and user-invocable:true. The skill does not request persistent system privileges or modify other skills. Note: the platform default allows autonomous invocation unless you disable it in agent settings; that is a platform-level policy rather than the skill requesting elevated persistence.