Back to skill
Skillv1.0.0

ClawScan security

Ads Audience Targeting · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignMar 3, 2026, 12:50 AM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
The skill is an instruction-only audience-segmentation advisor whose requested inputs and behavior match its stated purpose and it does not request credentials, installs, or system access.
Guidance
This skill appears coherent and low-risk: it only needs marketing/account context to produce audience segmentation recommendations and does not request credentials or install software. Before using it, ensure you: (1) do not paste sensitive account credentials or access tokens into prompts — provide high-level performance metrics or anonymized examples instead; (2) verify the skill's source or owner if you need to share real account IDs or proprietary customer data; (3) test with non-sensitive sample data to confirm outputs meet your compliance/privacy needs; and (4) if handing off actions to execution systems, ensure those downstream integrations ask separately for needed API credentials under your control.

Review Dimensions

Purpose & Capability
okName/description (audience segmentation and targeting for ad platforms) aligns with the SKILL.md instructions: it asks for campaign goals, scope, context, KPIs and produces segmentation, action plans, and handoff payloads. No unrelated capabilities or external services are requested.
Instruction Scope
okRuntime instructions are limited to marketing inputs (business_goal, scope, context, metrics) and generating recommendations, platform notes, and handoff fields. The SKILL.md does not instruct the agent to read system files, environment variables, credentials, or transmit data to unexpected endpoints.
Install Mechanism
okThis is an instruction-only skill with no install spec and no code files, so nothing is written to disk or installed. That is the lowest-risk install pattern and appropriate for a guidance/analysis skill.
Credentials
okThe skill declares no required environment variables, credentials, or config paths. The inputs it requests (account context, historical performance) are appropriate for an ad-targeting planner, but they may include sensitive account data provided by the user — the skill itself does not demand secrets or keys.
Persistence & Privilege
okalways is false and model invocation is allowed (default). The skill does not request persistent system presence, nor does it modify other skills or system settings.