Back to skill
Skillv1.0.0

ClawScan security

AI Frens Ambassador Program · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignFeb 11, 2026, 9:27 AM
Verdict
benign
Confidence
medium
Model
gpt-5-mini
Summary
Instruction-only marketing/onboarding content for an ambassador program; its requirements and instructions are consistent with the stated purpose and it does not request credentials or install code.
Guidance
This skill is essentially marketing and onboarding documentation for a crypto/token-based ambassador program. It does not request credentials or install code, which is good. Before installing or using it, consider: (1) do not share private keys or wallet seed phrases with the skill or in conversations; (2) the onboarding flow requires deploying a token and paying ETH gas — understand the financial cost and legal/regulatory implications of launching or promoting tokens in your jurisdiction; (3) when 'reporting back' feedback, avoid sharing private or personally identifying information from others; (4) verify the external links and the legitimacy of aifrens.lol independently (domain, team, audited contracts) before interacting with or promoting the project; and (5) if you plan to use this agent to engage others, be mindful of platform rules about promotion/spam and the reputational risk of representing a tokenized product.

Review Dimensions

Purpose & Capability
okThe skill's name and description (promoting an ambassador program and explaining how the platform and tokenomics work) match the SKILL.md content. There are no unexpected dependencies, binaries, or credentials required that would be unrelated to promotion/onboarding.
Instruction Scope
noteThe runtime instructions are limited to describing the platform, providing conversation templates and onboarding steps (including links). One thing to note: the skill encourages ambassadors to 'report back' what they hear from other agents — this implies collecting and relaying feedback from conversations, which is within the marketing scope but could raise privacy/reputational considerations depending on what ambassadors collect and share.
Install Mechanism
okNo install spec and no code files — instruction-only. That minimizes disk writes and arbitrary code execution risks.
Credentials
okRequires no environment variables, credentials, or config paths. Although the onboarding process described requires connecting a crypto wallet and paying gas (ETH) on Base, the skill itself does not request private keys or other secrets.
Persistence & Privilege
okalways is false and the skill is user-invocable; it does not request persistent or elevated platform privileges or attempt to modify other skills or system settings.