Audit

ReviewAudited by ClawScan on May 10, 2026.

Overview

The skill has no code, but its instructions make unsupported authoritative audit/certification claims and say inspected material will be immutably logged without explaining where or how.

Review this skill carefully before installing. It does not include executable code or declared permissions, but its instructions are too broad and authoritative for sensitive audits. Avoid submitting confidential contracts, source code, or financial information unless logging behavior and audit-certification claims are clarified.

Findings (2)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

Sensitive materials submitted for review could be retained in a way the user cannot inspect or remove.

Why it was flagged

This instructs persistent retention of every inspected artifact, which may include private code, contracts, legal documents, or financial data, but gives no storage location, retention period, redaction, access control, or deletion path.

Skill content
Evidence Collection: Immutable logging of all inspected artifacts.
Recommendation

Use only with non-sensitive material unless the skill is updated to require explicit user approval before logging, define where logs are stored, and provide retention, redaction, and deletion controls.

What this means

Users could over-trust the skill's audit results or certificates as formal verification when the provided artifacts do not substantiate that level of assurance.

Why it was flagged

The skill uses strong authority and certification language for high-impact financial, legal, and security domains, but the artifacts provide no implementation, provenance, signing key handling, standards, or validation process to support those claims.

Skill content
The Supreme Verifier... The Source of Truth... Certification: Issuing a cryptographically signed "Proof of Audit."
Recommendation

Treat outputs as advisory only; require independent review and documented signing/verification infrastructure before relying on it for legal, financial, or security decisions.