Back to skill
Skillv1.0.0

ClawScan security

Austine Daily Ops · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignMar 2, 2026, 1:55 PM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
Instruction-only daily-ops and travel-procurement assistant that contains templates and step-by-step guidance, with no installs, credentials, or external endpoints requested — behavior matches its description.
Guidance
This skill is coherent and low-risk: it only contains templates and operational instructions. Before installing or using it, (1) review any drafted messages before sending them to vendors/contacts, (2) do not paste payment credentials, account passwords, or other secrets into chat unless you intentionally want the agent to hold/send them, and (3) if you plan to let the agent act autonomously (have it contact vendors/execute bookings), be aware you'll need to provide credentials or integrations at that time — only do so through trusted channels. If you want further assurance, request an explicit statement from the skill author about whether it logs or persists user-provided contact/payment details and how those are stored/used.

Review Dimensions

Purpose & Capability
okThe name/description (daily ops + trip procurement) matches the SKILL.md and the two reference templates. There are no unrelated required binaries, env vars, or config paths requested.
Instruction Scope
okRuntime instructions are limited to collecting user constraints, producing prioritized lists, normalized quotes, recommendation options, and drafting next-step messages. The skill references only its included reference files and does not instruct reading system files, environment variables, or sending data to external endpoints.
Install Mechanism
okNo install spec and no code files — instruction-only. This is the lowest-risk install model (nothing written to disk by the skill).
Credentials
okNo required environment variables, credentials, or config paths are declared or referenced. The guidance to prepare communication drafts is reasonable for a sourcing/ops assistant and does not require secrets.
Persistence & Privilege
okalways:false and user-invocable:true. The skill does not request permanent presence or modification of other skills or system settings. disable-model-invocation is false (normal); nothing in the skill increases autonomous privileges beyond typical use.