Back to skill
Skillv1.0.4
ClawScan security
Krump · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignFeb 11, 2026, 9:26 AM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- This is an instruction-only dance skill (Krump) that contains textual teaching material and does not request credentials, install code, or access to system resources.
- Guidance
- This skill is content-only and internally consistent with its stated purpose — it doesn't request secrets or install code. Before installing, consider: (1) the SKILL.md notes the knowledge base only extends to 2017, so verify any historical or event claims if accuracy matters; (2) physical-movement guidance can cause injury — ensure the agent includes safety disclaimers and encourages users to learn moves under supervision; and (3) be mindful of cultural sensitivity when presenting community-origin information. If you want, provide the full SKILL.md for a line-by-line review or request the agent add safety and sourcing disclaimers.
Review Dimensions
- Purpose & Capability
- okThe skill's name and description match the content of SKILL.md (dance history, moves, fam system, events). Nothing requested (no env vars, binaries, or installs) is disproportionate to a teaching/reference skill.
- Instruction Scope
- okSKILL.md appears to be purely educational text about Krump technique, history, crews and events. It does not instruct the agent to read files, access environment variables, run commands, or transmit data to external endpoints.
- Install Mechanism
- okNo install specification or code files are present; this is lowest-risk instruction-only content and nothing will be written to disk or fetched during install.
- Credentials
- okThe skill declares no required environment variables, credentials, or config paths, which is appropriate for a read-only educational skill.
- Persistence & Privilege
- okalways is false and the skill does not request persistent or elevated privileges. Autonomous invocation (default) is allowed by platform policy and poses minimal risk here because the skill is content-only.
