Back to skill
Skillv1.0.0

ClawScan security

Ads Media Strategy · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignMar 4, 2026, 3:18 AM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
This is an instruction-only ad media planning skill whose inputs, outputs, and runtime instructions are coherent with its stated purpose and do not request credentials, installs, or unusual system access.
Guidance
This skill is an instruction-only planner and appears internally consistent for creating ad channel mixes and budgets. Before installing: confirm that any 'handoff payload' generated by the agent will not be automatically sent to external services (no endpoints are specified), and avoid supplying real account credentials or billing tokens in free-text inputs. If you plan to use the agent to perform live actions (execute orders, change campaign billing), require an explicit, separate integration that you control rather than pasting credentials into chat. Otherwise it is safe to install from an access/privilege perspective.

Review Dimensions

Purpose & Capability
okThe skill name and description (media/channel mix, budget allocation for ad platforms) match the SKILL.md content. No binaries, environment variables, or config paths are requested, which is proportionate for an advisory/strategy skill.
Instruction Scope
noteRuntime instructions are focused on strategy, test matrices, budget splits, and guardrails. One mildly ambiguous item: 'escalate with a structured handoff payload' — the skill doesn't specify an external endpoint or destination for such payloads, so reviewers should confirm downstream handling of any handoff data to avoid accidental disclosure of sensitive info. Otherwise the instructions stay within advertising strategy scope and do not direct reading of system files or credentials.
Install Mechanism
okNo install spec and no code files — the skill is instruction-only, which minimizes disk footprint and execution risk.
Credentials
okNo required environment variables, credentials, or config paths are declared. The SKILL.md does not reference accessing secrets or unrelated environment state.
Persistence & Privilege
okalways is false and the skill is user-invocable with normal autonomous invocation allowed. It does not request permanent presence or modifications to other skills or system-wide settings.