Back to skill
Skillv1.0.3
ClawScan security
Domain Keyword Intelligence - Find the Registration Trends · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignMar 25, 2026, 6:33 PM
- Verdict
- Benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- The skill's requests and runtime instructions align with its stated purpose (DomainKits domain-intel + web searches); it asks only for a DomainKits API key and contains no install or unrelated credential demands.
- Guidance
- This skill appears coherent with its stated purpose, but before installing: 1) only provide a DomainKits API key you trust — check DomainKits' docs for scopes, rate limits, and privacy/retention; 2) note the skill will perform web_search queries (platform-built-in) that may log/retain your search terms and the domains you investigate — avoid searching for highly sensitive targets; 3) monitor API usage and costs from DomainKits and the platform; 4) do not supply additional credentials or broader-scoped keys (AWS, GitHub, etc.); and 5) if you want tighter control, restrict the skill's invocation or review logs to ensure it only queries the expected endpoints.
Review Dimensions
- Purpose & Capability
- okName/description match the declared use of DomainKits MCP endpoints (keywords_trends, nrds) and web_search for catalyst research. The primary credential (DOMAINKITS_API_KEY) and the declared tools are appropriate and proportionate to domain‑trend analysis.
- Instruction Scope
- okSKILL.md instructs only to call DomainKits MCP tools and platform web_search, and to perform structured profiling (growth rates, com_ratio, forsale_pct, registrar dispersion, etc.). It does not ask to read local files, unrelated env vars, or transmit unrelated system data. It explicitly forbids speculative recommendations without web_search confirmation.
- Install Mechanism
- okNo install spec and no code files — instruction-only skill — so nothing will be downloaded or written to disk by the skill itself.
- Credentials
- okOnly the DOMAINKITS_API_KEY is declared as the primary credential and the SKILL.md examples reference that key. No unrelated secrets, system creds, or extraneous env vars are requested.
- Persistence & Privilege
- okFlags show always:false (not force-included). The skill does not request modification of other skills or system-wide settings; autonomous invocation is allowed but is the platform default.
