Back to skill
Skillv1.0.0

ClawScan security

Counterfactual Thinking · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignMar 12, 2026, 12:05 PM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
The skill is an instruction-only helper for structured counterfactual analysis and its declared requirements and instructions are coherent with that purpose.
Guidance
This skill is an instruction-only reasoning tool and appears coherent with its stated purpose. Risks are low from an installation standpoint, but be cautious when sharing real-world context: do not paste secrets, credentials, or private files into the conversation. Treat output as analytic guidance (not legal, medical, or safety-critical advice) and validate any decisions with domain experts or primary sources.

Review Dimensions

Purpose & Capability
okName and description match the content of SKILL.md; there are no unexpected binaries, credentials, or config paths requested. All declared capabilities are proportional to a thought‑exercise / analysis skill.
Instruction Scope
noteThe SKILL.md gives a broad, multi-step procedure for constructing counterfactuals and explicitly directs the agent to apply that framework to the user's current topic. It does not instruct any file reads, network calls, or credential access. Note: because the guidance is open-ended the agent may request user-provided context (which could include sensitive case details) to perform the analysis — this is expected behavior but users should avoid pasting secrets or private credentials.
Install Mechanism
okNo install spec and no code files — instruction-only. This is the lowest-risk install model; nothing will be written to disk by the skill itself.
Credentials
okThe skill requests no environment variables, credentials, or config paths. There are no disproportionate or unrelated permission requests.
Persistence & Privilege
okalways is false and the skill is user-invocable; it does not request persistent presence or elevated platform privileges.