Back to skill
Skillv2.0.1

ClawScan security

Vitamin · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignMar 18, 2026, 1:45 AM
Verdict
Benign
Confidence
high
Model
gpt-5-mini
Summary
The skill’s files, instructions, and requested environment are consistent with a local, offline vitamin/supplement tracker that stores data under ~/.local/share/vitamin; nothing indicates unexpected network access or unrelated credential requests.
Guidance
This skill appears to be a simple, offline CLI tracker that stores data at ~/.local/share/vitamin. If you install it, review the script (scripts/script.sh) yourself if you want extra certainty, and back up or inspect any existing files in ~/.local/share/vitamin before running. There are no network calls or credential requests in the provided files, but if future versions add installs or external endpoints re-check those changes.

Review Dimensions

Purpose & Capability
okName/description match the provided code and SKILL.md. The script implements local logging, export, search, and status commands consistent with a CLI vitamin tracker; no unrelated services or credentials are requested.
Instruction Scope
okSKILL.md and the script confine actions to the user's home directory (~/.local/share/vitamin). Commands read/write local .log files, produce exports, and show stats. There are no instructions to read unrelated system config, network endpoints, or external credentials.
Install Mechanism
okThis is an instruction-only skill with one included script; there is no install spec that downloads remote artifacts. Nothing is written outside the user's home data dir.
Credentials
okNo required env vars or credentials. The script uses HOME to build a per-user data directory (~/.local/share/vitamin), which is proportional to the tool's purpose.
Persistence & Privilege
okalways is false, the skill does not request elevated privileges or alter other skills or system-wide agent settings. It only creates/uses its own data directory under the user's home.