1. The input is a Word template document; 2. Analyze the structure of this template, including: 1) Font styles, sizes, etc., for headings, body text, etc.; 2) Content: the general structure of each paragraph; 3) Multimedia elements: images, text, tables (including metric data, etc.) 3. Generate documents that conform to the template structure based on the given data 1) A knowledge base, or multiple documents; 2) Relationship tables (or CSV files), SQL query results, etc.
PassAudited by ClawScan on May 1, 2026.
Overview
The skill is a coherent instruction-only document-generation assistant, with disclosed local file/tool use and cloud model processing that users should be aware of before giving it sensitive documents.
This appears safe for its stated purpose, but install it only if you are comfortable letting the agent read the documents and data you provide, write generated outputs, run limited local data-processing commands, and use the disclosed cloud model for document analysis and generation.
Findings (3)
Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.
The agent could read input files, write outputs, and run local commands while helping process document data.
The skill declares broad local read, write, and command execution tools. The README ties these tools to document reading, result writing, and data processing, so this appears purpose-aligned, but users should understand the local authority being granted.
tools: - read - write - exec
Use it with files you intentionally provide, review generated outputs before relying on them, and avoid granting access to unrelated directories or sensitive local data.
On case-sensitive systems, the skill may fail to load the intended prompt or behave inconsistently.
The declared entry file uses 'PROMPT.md', while the supplied manifest contains 'prompt.md'. This is a packaging consistency issue rather than evidence of malicious behavior.
entry: PROMPT.md
Confirm the entry filename matches the packaged prompt file before publishing or installing.
Sensitive templates, reports, CSVs, or knowledge-base content may be included in prompts or context sent to the cloud model.
The README discloses that a cloud model is used for template understanding, multi-source data summarization, and document generation. This is expected for the skill, but it means user-provided documents and data may be processed through an external model.
本 Skill 设计为调用云端大模型: - 模型名称:glm-5
Do not provide confidential or regulated data unless your organization approves use of the named cloud model for that content.
