Back to skill
Skillv1.0.0

ClawScan security

China Ecommerce Copywriter · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignMar 28, 2026, 6:04 PM
Verdict
Benign
Confidence
high
Model
gpt-5-mini
Summary
The skill is an instruction-only Chinese e‑commerce copywriter that asks for no credentials or installs and its instructions and example code are consistent with its stated purpose.
Guidance
This skill appears internally consistent and safe to install as it is instruction-only and requests no credentials. Before using it in production: (1) treat all generated marketing copy as drafts — manually review for compliance with platform rules, advertising law, trademark claims, and factual accuracy; (2) do not paste sensitive customer data into prompts when generating copy; (3) understand the embedded Python is an example only and will not run automatically; if you later add integrations (APIs, publishing automation), expect those to require credentials and warrant a new security review.

Review Dimensions

Purpose & Capability
okThe name and description (Taobao/JD/Pinduoduo copywriting) match the SKILL.md content. There are no declared environment variables, binaries, or config paths that would be unnecessary for a text-generation helper.
Instruction Scope
noteThe SKILL.md provides detailed guidance and platform-specific constraints and includes an embedded Python example for local usage. The file does not instruct the agent to read system files, access environment variables, or transmit data to external endpoints. Note: the Python snippet is illustrative only — there are no code files to execute as part of installation.
Install Mechanism
okNo install spec or code files are present (instruction-only), so nothing will be written to disk or downloaded during install. This is the lowest-risk install profile.
Credentials
okThe skill declares no required environment variables, credentials, or config paths. Requested capabilities are proportional to a text-generation/copywriting helper.
Persistence & Privilege
notealways:false (default) and the skill may be invoked autonomously by the agent (platform default). Autonomous invocation is normal; this skill does not request elevated persistence or modify other skills/configurations.