https://clawhub.ai/api/v1/skills/project-keeper/file?path=SKILL.md&version=1.0.1
github.com/clawhub.ai/project-keeper
Scanned Thu, 28 May 2026 15:25:14 GMT
Scan ID crawl-dvqgptv9295sxbdqs7n1dr82 · 1ms
D
SCORE 30 / 100
Verdict: Do not install
1 critical finding.
This skill contains semantic prompt-injection patterns plus 1 other issue listed below.
1 critical0 high1 medium10 rules passed
Why grade D?
score · 30 / 100The current grade reflects 1 critical finding (any single CRIT → D).
1 CRIT0 HIGH1 MED0 LOW
To reach a higher grade
- CReach Ctarget score 55
Resolve all 1 CRIT findings.
- BReach Btarget score 75
Resolve all 1 CRIT.
- AReach Atarget score 95
Resolve all 1 CRIT.
Thresholds are documented at /docs/grading. Source-of-truth is the grade() function in @skillox/scanner.
Findings · ordered by severity
critInstruction-injection pattern: covert-addThe skill contains a phrase that matches a known prompt-injection pattern (covert-add). Agents may treat this as a system-level directive rather than user content.▾
Instruction-injection pattern: covert-add
The skill contains a phrase that matches a known prompt-injection pattern (covert-add). Agents may treat this as a system-level directive rather than user content.
51```
52
53This file isn't the only file you'll create, but it's the most vital of all. It stores the core principles and main aims of the project along with the plans for it. Think of this file as the onboarding and documentation of work for another agent (most probably your future self) who knows NOTHING about this project. Furthermore, try to extract info from the user about the details and focuses of this project if not mentioned and include them in their fitting sections. DO NOT copy the filled in data directly from this template, think of this as an example submission of a form you're filling out.← covert-add pattern — agent may treat as system directive
54
medNo capability manifest declaredThe skill ships without a `manifest.yaml` or `capabilities` block in its frontmatter. Without a manifest, the runtime cannot enforce what this skill is permitted to do.rule: no-manifest▾
No capability manifest declared
The skill ships without a `manifest.yaml` or `capabilities` block in its frontmatter. Without a manifest, the runtime cannot enforce what this skill is permitted to do.
rule:
no-manifestskillox.io/r/crawl-dvqgptv9295sxbdqs7n1dr82