Back to skill
Skillv1.0.3
ClawScan security
communication-coach · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignApr 12, 2026, 3:23 AM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- An instruction-only communication-coach that matches its description, requests no env vars/binaries/install, and contains no code or unexpected endpoints.
- Guidance
- This skill is internally consistent and low-risk: it is instruction-only and asks for nothing extra. Before using, avoid pasting secrets or highly sensitive personal data (the skill will process any text you provide). Also note the author/homepage are unknown — if provenance matters, prefer skills from a known source. If you plan to allow autonomous invocation in an agent, remember the skill will be run by the agent without additional prompts (platform default); that is normal but worth considering for sensitive environments.
Review Dimensions
- Purpose & Capability
- okName/description (沟通教练) align with the SKILL.md content: challenge and translation of user-provided text. The skill requires no binaries, credentials, or config paths — nothing extraneous is requested for the stated purpose.
- Instruction Scope
- okSKILL.md contains only runtime instructions about asking clarifying/challenging questions and translating technical phrasing for different audiences. It does not instruct reading files, system paths, or transmitting data to external endpoints beyond the normal agent model invocation.
- Install Mechanism
- okNo install spec and no code files — instruction-only. This minimizes on-disk execution and third-party downloads, which is appropriate for a coaching/FAQ-style skill.
- Credentials
- okThe skill declares no environment variables, secrets, or primary credential. That is proportionate to a conversational coaching tool that only needs the user's pasted text.
- Persistence & Privilege
- okalways is false and the skill does not request persistent system presence or modify other skills. Autonomous model invocation is allowed by platform default but is normal for this type of skill.
