web-replication
Analysis
This instruction-only skill is coherently aimed at copying the look of public websites and includes permission checks, but users should set clear crawl limits and use only trusted browser tooling.
Findings (2)
Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.
Checks for instructions or behavior that redirect the agent, misuse tools, execute unexpected code, cascade across systems, exploit user trust, or continue outside the intended task.
Recursively explore every public page of the target website... save that page’s screenshots, component interaction records, and related asset files
This authorizes broad browser-driven crawling and capture of a website’s public presentation; it is central to the skill’s purpose and bounded by public-only and authorization language, but users should scope it carefully.
This workflow depends on either Playwright MCP or the agent-browser skill. As long as at least one of them is installed and available, the workflow can run normally.
The skill relies on external browser automation tooling that is not included in the artifact set or install spec; this is expected for the workflow but means the user must trust those separate tools.
