Back to skill
Skillv1.0.0
ClawScan security
Soul · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignMar 16, 2026, 9:21 AM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- An instruction-only social assistant for the Soul platform whose declared purpose, instructions, and resource requirements are consistent and do not request credentials or install code.
- Guidance
- This skill is an instruction-only assistant that gives advice about using the Soul social app; it does not request credentials or install code, which keeps its footprint minimal. Before installing, confirm you trust the skill author (no homepage or clear source is provided) — instruction-only content can still be misleading or out-of-date. If you plan to let an agent perform actions on your behalf (posting, messaging, or connecting accounts), ensure those actions require explicit authorization and review any future updates that add network calls or environment variables. Avoid sharing personal or financial information in chats and follow the skill's own safety guidance (do not teach or enable abusive/PUA tactics, and report scams requiring money).
Review Dimensions
- Purpose & Capability
- okName/description (Soul 社交助手) match the SKILL.md content: guidance on matching, profile, content creation, community interaction. The skill does not request unrelated credentials, binaries, or config paths.
- Instruction Scope
- okSKILL.md contains only prescriptive guidance for social use (matching tips, profile/content advice, safety reminders). It does not instruct the agent to read files, access environment variables, perform network calls, or transmit data to external endpoints.
- Install Mechanism
- okNo install spec and no code files; this is instruction-only so nothing is written to disk or fetched during install.
- Credentials
- okNo required environment variables, credentials, or config paths are declared; the skill's behavior does not require elevated access or secrets.
- Persistence & Privilege
- okalways is false and the skill is user-invocable; autonomous model invocation is allowed (platform default) but there are no additional persistence or privilege requests from the skill itself.
