UmowaGenerator

PassAudited by ClawScan on May 3, 2026.

Overview

The skill appears to be a purpose-aligned Polish contract generator with no evidence of exfiltration or destructive behavior, but it handles sensitive identity details and advertises optional email/payment/legal-reliance flows users should verify.

This skill looks coherent for generating Polish contract templates. Before installing or using it, avoid entering real PESEL/NIP data until necessary, review all legal text yourself, independently verify any off-platform PRO payment link, and do not use email-sending features for sensitive documents unless you understand where the data goes.

Findings (4)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

Users may place national identifiers and addresses into the agent conversation or generated documents.

Why it was flagged

The skill expects sensitive identity and address details to draft contracts; this is purpose-aligned but important for users to notice.

Skill content
Dane stron: imię, nazwisko, adres, PESEL/NIP
Recommendation

Use placeholders while drafting when possible, and provide real PESEL/NIP or address data only when needed for the final document.

What this means

If used, contracts containing personal or business details could be sent to another party by email.

Why it was flagged

The advertised PRO email feature would transmit generated legal documents outside the local drafting flow, but the artifacts do not define the email provider, controls, or recipient-confirmation process.

Skill content
Wysyłanie mailem — wyślij umowę bezpośrednio z aplikacji (PRO)
Recommendation

Before using any email-sending feature, confirm the recipient, provider, consent, and whether the document contains sensitive identifiers.

What this means

A user might treat the generated contract as legally sufficient for an important transaction without independent review.

Why it was flagged

The wording may encourage reliance on generated legal documents without professional review; this is not malicious, but it is a trust-sensitive claim.

Skill content
Tworzy czytelne, zgodne z Kodeksem Cywilnym umowy ... profesjonalne umowy prawne bez prawnika
Recommendation

Treat generated contracts as templates and consult a qualified lawyer or trusted advisor for high-value or unusual agreements.

What this means

Users have less external context for verifying the author, updates, or support path.

Why it was flagged

The artifacts do not provide an external source repository or homepage for independent provenance checks.

Skill content
Source: unknown; Homepage: none
Recommendation

Install only if you trust the registry listing and reviewed artifacts; be cautious with any later PRO code, payment link, or update not included in this review.