BookNotes Reading Notes and Book Tracker

AdvisoryAudited by Static analysis on May 4, 2026.

Overview

No suspicious patterns detected.

Findings (0)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

You are relying on the registry-provided artifacts rather than a clearly linked upstream project.

Why it was flagged

The package does not provide a verifiable upstream source or homepage in the registry metadata, so users cannot easily compare the registry package to an external repository.

Skill content
Source: unknown; Homepage: none
Recommendation

Review the included files before installing and prefer versions from a trusted publisher or verifiable source when available.

What this means

Private reading notes or quoted text may persist locally and could influence future summaries or responses if the agent uses them as context.

Why it was flagged

The skill stores user-provided notes persistently and may reuse them for summaries or cross-references in later interactions.

Skill content
- **Cross-reference** — connects related ideas across books
- **Book summaries** — auto-generated from your notes
...
**DATA DISCLAIMER:** This software processes and stores data locally on your system.
Recommendation

Keep backups, avoid storing highly sensitive material unless you are comfortable with local persistence, and treat stored quotes/notes as content rather than instructions.