Promptify Skill

PassAudited by ClawScan on May 1, 2026.

Overview

Promptify is an instruction-only prompt-improvement skill with disclosed, purpose-aligned use of local code search, web research, and optional clipboard command output.

This skill appears safe to install as an instruction-only prompt optimizer. Before using +deep, be comfortable with the agent reading relevant local project files; before using +web, remove confidential details from the prompt; and inspect any generated pbcopy command before running it.

Findings (3)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

If used on a private project, relevant file names and file contents may be read by the agent to improve the prompt.

Why it was flagged

The skill can inspect local project structure and read relevant files during codebase research. This is disclosed and aligned with optimizing project-specific prompts, but it gives the agent access to local code context.

Skill content
Use Glob and LS to understand... Use Grep and Read to find...
Recommendation

Use +deep or codebase auto-detection only in projects you are comfortable sharing with the agent, and review the announced research scope.

What this means

Sensitive project names, internal APIs, or private details included in a prompt could become part of web-search queries if web research is used.

Why it was flagged

The skill may send prompt-derived topics to web search/fetch tools. This is disclosed and purpose-aligned for current best practices, but it can expose search terms derived from the user's prompt to external web tooling.

Skill content
Use WebSearch for: "[technology] best practices 2025"... Use WebFetch - Retrieve specific documentation pages
Recommendation

Do not use +web, or remove sensitive identifiers first, when the prompt contains confidential information.

What this means

Running a generated clipboard command without checking it could fail or behave unexpectedly if the prompt text is not safely quoted.

Why it was flagged

The skill asks the agent to output a shell command for copying the optimized prompt to the clipboard. It is not instructed to execute the command automatically, but users should inspect any generated shell snippet before running it, especially if the prompt contains quotes or shell metacharacters.

Skill content
2. `echo 'PROMPT' | pbcopy`
Recommendation

Prefer copying the prompt directly, or inspect and safely quote any generated pbcopy command before running it.