Back to skill
Skillv1.0.1
ClawScan security
Cinemas in France · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignMar 3, 2026, 8:50 AM
- Verdict
- Benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- The skill is an instruction-only connector for the public data.culture.gouv.fr dataset and its requirements and instructions are consistent with that purpose.
- Guidance
- This skill appears coherent and limited to querying a public French government dataset; no credentials or installs are required. Before using, consider: (1) proximity queries require you to supply coordinates — treat those as personal data you may not want to share automatically; (2) the agent will make outbound network requests to data.culture.gouv.fr when invoked, so only enable the skill for agents you trust to perform those requests; (3) if you want to restrict autonomous behavior, keep model-invocation disabled for agents that should not call skills without your confirmation.
Review Dimensions
- Purpose & Capability
- okThe name and description claim access to the French governmental cinema dataset and the SKILL.md contains only query examples and field descriptions for that dataset. There are no unrelated requested binaries, environment variables, or install steps that would be disproportionate to the stated purpose.
- Instruction Scope
- okThe instructions are limited to constructing HTTP queries against the public API (data.culture.gouv.fr) and explain filters, pagination, selection and aggregation. The SKILL.md does not ask the agent to read local files, environment variables, or forward results to any third-party endpoint. Note: proximity examples use USER_LON/USER_LAT placeholders — using them would require the agent to obtain user location data, which is expected for proximity searches but is personal data when supplied.
- Install Mechanism
- okNo install spec and no code files are present; this is instruction-only so nothing is written to disk or downloaded during install.
- Credentials
- okThe skill declares no required environment variables, credentials, or config paths. That aligns with the SKILL.md statement that no API key is required for the public dataset.
- Persistence & Privilege
- okalways is false and the skill does not request persistent or elevated privileges nor does it instruct modifying other skills or system-wide agent settings.
