Back to skill
Skillv1.0.0

ClawScan security

Biz Hospitality · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignMar 23, 2026, 7:56 AM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
The skill is an instruction-only hospitality planning helper whose requested inputs and outputs match its stated purpose and it makes no unexpected environment, install, or credential demands.
Guidance
This skill appears internally consistent and low-risk from a platform perspective. Considerations before installing: avoid supplying unnecessary sensitive personal data (full IDs, passport numbers, etc.) in guest_profile fields; verify any real-world actions (booking, purchases, gift procurement) are performed through trusted systems with appropriate credentials rather than via free-text outputs; review culturally sensitive recommendations for accuracy; if you prefer explicit user consent for autonomous runs, restrict or monitor agent invocation settings.

Review Dimensions

Purpose & Capability
okName, description, inputs, and outputs are aligned: the skill asks for guest and visit details and produces reception plans, seating, dining, etiquette, gifts, and follow-up — all coherent with business hospitality.
Instruction Scope
okSKILL.md contains only schema-like runtime instructions (inputs/outputs and examples). It does not instruct the agent to read system files, access environment variables, call unexpected external endpoints, or collect unrelated data.
Install Mechanism
okNo install spec and no code files are present (instruction-only), so nothing is written to disk or downloaded during install.
Credentials
okThe skill requires no environment variables, credentials, or config paths — this is proportionate to a hospitality-planning assistant.
Persistence & Privilege
okalways is false and model invocation is enabled (the platform default). That normal autonomy is not by itself a concern given the skill's limited scope and lack of requested secrets.