Back to skill
Skillv1.0.1

ClawScan security

fanqie-masterclass · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignFeb 27, 2026, 11:36 AM
Verdict
benign
Confidence
medium
Model
gpt-5-mini
Summary
This is an instruction-only course for writing platform-specific short fiction; its files and runtime instructions are internally consistent with that purpose, but it recommends third‑party workflows and copyright‑risky 'high‑imitation' tactics that merit user caution.
Guidance
The package itself is coherent with its stated goal (teaching platform‑targeted short‑story tactics). Before installing or using it, consider: 1) don't paste or upload copyrighted or sensitive third‑party text into external workflows or other LLMs without checking rights; the course advocates heavy 'high‑imitation' techniques that can cross into plagiarism or platform policy violations. 2) The materials call out an external workflow URL and recommend sending segments to other LLMs — avoid sending personal data, unpublished manuscripts, or proprietary content to unknown third parties. 3) Some operational advice (contract/tax/W‑8BEN wording) may be legally or factually sensitive — verify with a tax/legal professional rather than following it blindly. 4) The writing guidance includes violent/explicit examples and aggressive monetization tactics; ensure you comply with the target platforms' content and copyright policies. If you want higher assurance, ask the publisher for the origin/source of the skill (homepage/author) and validate the external workflow URL and any third‑party services before using them.
Findings
[no_regex_matches] expected: This is an instruction-only skill composed of Markdown references and SKILL.md; the static scanner found no code to analyze. That absence of findings is expected but does not guarantee safety of content or external links.

Review Dimensions

Purpose & Capability
okName/description (番茄小说爆款写作训练营) match the provided documents and modes (learn/quick/diagnose/polish). The skill requests no binaries, no env vars, no installs and contains only teaching materials and prompts — nothing appears unrelated to the stated writing/monetization purpose.
Instruction Scope
noteSKILL.md and all references are focused on generating/diagnosing/polishing short fiction and on multi‑platform distribution. However the instructions encourage: (1) copying external reference texts into a '备忘录' and using them as examples; (2) using third‑party AI services and an external workflow URL (https://xingyuexiezuo.com/?workflow=1906) to run one‑click '成文' operations; and (3) explicit '高仿/移花接木' techniques that increase the risk of producing derivative/copyrighted content. These are within the skill's stated pedagogical scope but expand where user content may be sent — exercise caution about what you copy/paste or send to external services.
Install Mechanism
okNo install spec and no code files — the skill is instruction-only. That minimizes filesystem/binary risk; nothing will be downloaded or executed by an installer as part of this skill package.
Credentials
okThe skill declares no required environment variables, credentials, or config paths and the instructions do not request secrets or unrelated system access. Requested resources (templates, prompts, references) are all bundled text files in the repo.
Persistence & Privilege
okFlags show always:false and normal agent invocation. The skill does not request persistent presence or elevated platform privileges; it does not modify other skills or agent-wide config based on the provided materials.