Back to skill
Skillv0.1.0

ClawScan security

Flash Sale · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignMar 19, 2026, 4:46 PM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
This is an instruction-only marketing SOP for running limited-time flash sales; it requests no installs, credentials, or system access and its requirements match its stated purpose.
Guidance
This skill is a harmless, text-only SOP for running flash-sales and appears internally consistent. Before using: remember it provides high-level guidance only (you'll still need to implement tracking, backend rules and compliance checks in your systems); validate any pricing/promotional language against platform rules and local regulations; test rules in a staging environment to avoid incorrect discounts or fulfillment issues. Because it’s instruction-only, there is no code risk from installation, but verify any suggested integrations (UTM, order tags, attribution) are implemented securely by your engineering team.

Review Dimensions

Purpose & Capability
okThe name/description (限时促销/flash sale) matches the SKILL.md content: marketing strategy, SOP, metrics, tracking and implementation guidance. No unrelated credentials, binaries, or platform access are requested.
Instruction Scope
okSKILL.md contains high-level and operational steps (rules design, tracking parameters, backend configuration guidance, metrics and monitoring). It does not instruct the agent to read files, access environment variables, call external endpoints, or transmit data. All instructions remain within the marketing/operations scope.
Install Mechanism
okNo install spec and no code files — instruction-only. Nothing will be written to disk or downloaded as part of an install.
Credentials
okThe skill declares no environment variables, credentials, or config paths. Although it discusses tracking IDs and backend configuration conceptually, it does not request secrets or access to external services.
Persistence & Privilege
okalways is false and the skill is user-invocable (normal). It does not request persistent presence, nor does it modify other skills or system settings.