Back to skill
Skillv1.0.0
ClawScan security
Fenbi · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignMar 16, 2026, 9:19 AM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- This is a coherent, instruction-only Chinese exam-prep assistant that requests no credentials, installs, or system access and its instructions align with the stated purpose.
- Guidance
- This skill appears to do exactly what it says: provide Chinese-language exam preparation guidance. It requests no installs or credentials so technical risk is low. Points to consider before installing: (1) Source/maintainer information is missing (no homepage) — prefer skills with a known publisher if you need long-term support or updates. (2) Content quality and correctness: verify example solutions and study plans against trusted textbooks or official past papers (LLMs can hallucinate or simplify). (3) Privacy: although the skill doesn't request credentials, avoid submitting highly sensitive personal data in prompts. (4) Autonomous invocation is allowed by default on the platform; that is normal but if you want to control when it runs, restrict invocation in your agent settings. Overall this skill is internally consistent and low-risk, but evaluate pedagogical accuracy and publisher trust before wide deployment.
Review Dimensions
- Purpose & Capability
- okName, description, and SKILL.md content all describe an exam-preparation assistant (公务员/教师资格等). There are no unexpected dependencies, binaries, or credentials requested that would be unrelated to that purpose.
- Instruction Scope
- okSKILL.md contains persona, pedagogy, and step-by-step guidance for teaching/exam prep. It does not instruct reading system files, environment variables, external endpoints, or any unrelated data collection. Scope stays within educational assistance.
- Install Mechanism
- okNo install spec or code files — instruction-only. This minimizes disk/network install risk.
- Credentials
- okThe skill declares no required environment variables, no credentials, and no config paths. Requested access is proportionate to an instructional assistant.
- Persistence & Privilege
- okFlags show default behavior (not always-on). The skill does not request elevated persistence or to modify other skills or system-wide settings.
