Back to skill
Skillv1.0.0

ClawScan security

Buddha Companion · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignMar 14, 2026, 2:13 AM
Verdict
Benign
Confidence
high
Model
gpt-5-mini
Summary
This is an instruction-only Buddhist dialogue assistant whose declared purpose matches its instructions and it requests no credentials, binaries, or installs.
Guidance
This skill is instruction-only and appears coherent with its stated purpose: it contains conversational rules and Buddhist practice pointers and asks for no credentials or installs. Consider: (1) content is religious/spiritual guidance — verify it matches your tradition or expectations and is appropriate for the user; (2) it is not a substitute for professional mental-health advice — avoid relying on it for crisis situations; (3) because it is purely instructional there is no code-based attack surface, but review outputs for harmful or biased guidance before using in automated flows.

Review Dimensions

Purpose & Capability
okThe name and description (Buddhist practice / dialog coach) align with the SKILL.md content: guidance on core doctrines, conversational techniques, and practice checkpoints. There are no unrelated requirements (no credentials, binaries, or external integrations) that would contradict the stated purpose.
Instruction Scope
okSKILL.md contains only dialog/teaching guidelines (how to identify attachments, stop/observe/ask, etc.). It does not instruct the agent to read files, access environment variables, call external endpoints, or collect/transmit data outside the conversation.
Install Mechanism
okThere is no install spec and no code files — the skill is purely instruction-based, so nothing is written to disk or executed beyond the agent following the provided conversational guidance.
Credentials
okThe skill requires no environment variables, credentials, or config paths. Requested capabilities are proportional to a chat-based religious/practice assistant.
Persistence & Privilege
okalways is false and the skill does not request persistent system presence or modify other skills/configuration. Model invocation is allowed (the platform default) but that is normal and expected for a conversational skill.