Back to skill
Skillv1.0.0
ClawScan security
Ads Audience Targeting · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignMar 3, 2026, 12:50 AM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- The skill is an instruction-only audience-segmentation advisor whose requested inputs and behavior match its stated purpose and it does not request credentials, installs, or system access.
- Guidance
- This skill appears coherent and low-risk: it only needs marketing/account context to produce audience segmentation recommendations and does not request credentials or install software. Before using it, ensure you: (1) do not paste sensitive account credentials or access tokens into prompts — provide high-level performance metrics or anonymized examples instead; (2) verify the skill's source or owner if you need to share real account IDs or proprietary customer data; (3) test with non-sensitive sample data to confirm outputs meet your compliance/privacy needs; and (4) if handing off actions to execution systems, ensure those downstream integrations ask separately for needed API credentials under your control.
Review Dimensions
- Purpose & Capability
- okName/description (audience segmentation and targeting for ad platforms) aligns with the SKILL.md instructions: it asks for campaign goals, scope, context, KPIs and produces segmentation, action plans, and handoff payloads. No unrelated capabilities or external services are requested.
- Instruction Scope
- okRuntime instructions are limited to marketing inputs (business_goal, scope, context, metrics) and generating recommendations, platform notes, and handoff fields. The SKILL.md does not instruct the agent to read system files, environment variables, credentials, or transmit data to unexpected endpoints.
- Install Mechanism
- okThis is an instruction-only skill with no install spec and no code files, so nothing is written to disk or installed. That is the lowest-risk install pattern and appropriate for a guidance/analysis skill.
- Credentials
- okThe skill declares no required environment variables, credentials, or config paths. The inputs it requests (account context, historical performance) are appropriate for an ad-targeting planner, but they may include sensitive account data provided by the user — the skill itself does not demand secrets or keys.
- Persistence & Privilege
- okalways is false and model invocation is allowed (default). The skill does not request persistent system presence, nor does it modify other skills or system settings.
