Wasm Spa Autofix React Imports

PassAudited by ClawScan on May 1, 2026.

Overview

This instruction-only skill coherently helps fix React/TSX import and bundler issues, with no evidenced credential use, hidden execution, or unrelated behavior.

This appears safe for its stated purpose. Before installing, understand that it is meant to inspect project context and produce source-code patches, so review diffs before applying them and keep it limited to the intended React/WASM project.

Findings (2)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

The agent may look through parts of the project and propose code changes, which could affect build behavior if applied without review.

Why it was flagged

The skill can use available file-reading context beyond the current file to infer imports. This is purpose-aligned for fixing source code, but users should be aware it may inspect nearby repository files.

Skill content
If possible, read additional project files (when the tooling allows) to find existing imports/exports
Recommendation

Use dry-run or review generated diffs before applying them, and keep the projectRoot scoped to the intended repository.

What this means

Users have less registry-level information for verifying who authored the skill or where it is maintained.

Why it was flagged

The registry metadata does not provide a source URL or homepage, which limits provenance verification. The risk is reduced because the artifact is instruction-only and has no install script or code files.

Skill content
Source: unknown; Homepage: none
Recommendation

If provenance matters for your workflow, verify the publisher and any referenced repository before relying on the skill.