Back to skill
Skillv1.0.0

ClawScan security

Brainstorm Facilitator · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 29, 2026, 4:32 AM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
The skill is an instruction-only brainstorming assistant that only needs user-provided brief data and its instructions match the described Six Hats methodology — there are no installs, credentials, or suspicious behaviors.
Guidance
This skill appears internally consistent and low-risk: it only follows a structured brainstorming procedure and asks for user-provided brief details. Before using it, avoid pasting secrets or private data into the brief (API keys, full customer records, internal credentials). Treat its outputs as creative guidance — verify legal, regulatory, or safety implications yourself before acting, and watch for hallucinated facts or unsupported claims in proposed concepts.

Review Dimensions

Purpose & Capability
okName and description (Six Hats brainstorming producing three concepts) match the SKILL.md instructions exactly; no unrelated capabilities or external services are requested.
Instruction Scope
okRuntime instructions are limited to framing the brief, running the six-hat thinking process, synthesizing three concepts, and scoring them. There are no directives to read system files, environment variables, network endpoints, or to exfiltrate data.
Install Mechanism
okNo install spec and no code files — instruction-only. Nothing will be written to disk or downloaded during install.
Credentials
okThe skill declares no required environment variables, credentials, or config paths. User input (theme, constraints, etc.) is the only data it needs.
Persistence & Privilege
okalways is false and the skill is user-invocable (normal). It does not request persistent presence, system-level changes, or access to other skills' configs.