Back to skill
Skillv1.0.0

ClawScan security

Fenbi · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignMar 16, 2026, 9:19 AM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
This is a coherent, instruction-only Chinese exam-prep assistant that requests no credentials, installs, or system access and its instructions align with the stated purpose.
Guidance
This skill appears to do exactly what it says: provide Chinese-language exam preparation guidance. It requests no installs or credentials so technical risk is low. Points to consider before installing: (1) Source/maintainer information is missing (no homepage) — prefer skills with a known publisher if you need long-term support or updates. (2) Content quality and correctness: verify example solutions and study plans against trusted textbooks or official past papers (LLMs can hallucinate or simplify). (3) Privacy: although the skill doesn't request credentials, avoid submitting highly sensitive personal data in prompts. (4) Autonomous invocation is allowed by default on the platform; that is normal but if you want to control when it runs, restrict invocation in your agent settings. Overall this skill is internally consistent and low-risk, but evaluate pedagogical accuracy and publisher trust before wide deployment.

Review Dimensions

Purpose & Capability
okName, description, and SKILL.md content all describe an exam-preparation assistant (公务员/教师资格等). There are no unexpected dependencies, binaries, or credentials requested that would be unrelated to that purpose.
Instruction Scope
okSKILL.md contains persona, pedagogy, and step-by-step guidance for teaching/exam prep. It does not instruct reading system files, environment variables, external endpoints, or any unrelated data collection. Scope stays within educational assistance.
Install Mechanism
okNo install spec or code files — instruction-only. This minimizes disk/network install risk.
Credentials
okThe skill declares no required environment variables, no credentials, and no config paths. Requested access is proportionate to an instructional assistant.
Persistence & Privilege
okFlags show default behavior (not always-on). The skill does not request elevated persistence or to modify other skills or system-wide settings.