Back to skill
Skillv1.0.3

ClawScan security

communication-coach · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 12, 2026, 3:23 AM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
An instruction-only communication-coach that matches its description, requests no env vars/binaries/install, and contains no code or unexpected endpoints.
Guidance
This skill is internally consistent and low-risk: it is instruction-only and asks for nothing extra. Before using, avoid pasting secrets or highly sensitive personal data (the skill will process any text you provide). Also note the author/homepage are unknown — if provenance matters, prefer skills from a known source. If you plan to allow autonomous invocation in an agent, remember the skill will be run by the agent without additional prompts (platform default); that is normal but worth considering for sensitive environments.

Review Dimensions

Purpose & Capability
okName/description (沟通教练) align with the SKILL.md content: challenge and translation of user-provided text. The skill requires no binaries, credentials, or config paths — nothing extraneous is requested for the stated purpose.
Instruction Scope
okSKILL.md contains only runtime instructions about asking clarifying/challenging questions and translating technical phrasing for different audiences. It does not instruct reading files, system paths, or transmitting data to external endpoints beyond the normal agent model invocation.
Install Mechanism
okNo install spec and no code files — instruction-only. This minimizes on-disk execution and third-party downloads, which is appropriate for a coaching/FAQ-style skill.
Credentials
okThe skill declares no environment variables, secrets, or primary credential. That is proportionate to a conversational coaching tool that only needs the user's pasted text.
Persistence & Privilege
okalways is false and the skill does not request persistent system presence or modify other skills. Autonomous model invocation is allowed by platform default but is normal for this type of skill.