Precedent

Security checks across static analysis, malware telemetry, and agentic risk

Overview

The supplied artifacts show a coherent legal-reference skill with documented local shell-script commands and no evidence of credential use, network access, or destructive behavior.

This appears safe to install from a security perspective based on the supplied artifacts. Treat it as general legal reference material rather than legal advice, and verify important legal conclusions against current jurisdiction-specific sources.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Risk analysis

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

Using the skill may run the included local script, which the supplied artifacts show as a way to display legal-reference material.

Why it was flagged

The skill is invoked through an included Bash script. This is documented and appears aligned with the reference-tool purpose, but it is still local code execution from the installed skill.

Skill content
scripts/script.sh intro
Recommendation

Review the included script before installing if you are cautious about local code execution, and invoke only the documented commands you intend to use.