Back to skill
Skillv0.3.0

ClawScan security

Company Investment Research · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignMar 5, 2026, 8:47 AM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
This is an instruction-only investment research framework and templates; its declared requirements, instructions, and files are coherent with the stated purpose and do not request unexpected access to credentials, binaries, or external install artifacts.
Guidance
This skill is a safe, purely instructional template for producing investment memos. Before using: (1) verify any third-party data you request (Bloomberg/FactSet/etc.)—the skill does not include those feeds; (2) do not provide secrets or paid-account credentials to the agent; (3) validate numeric outputs and assumptions (LLMs can hallucinate financials); and (4) confirm licensing/attribution if you republish templates or use them commercially.

Review Dimensions

Purpose & Capability
okName/description (investment research framework) match the provided SKILL.md and reference docs. No binaries, credentials, or unrelated capabilities are requested.
Instruction Scope
okSKILL.md and reference files are templates and checklists for analyst workflows. They do not instruct the agent to read system files, access credentials, call unknown external endpoints, or exfiltrate data.
Install Mechanism
okNo install spec and no code files; this is instruction-only so nothing is downloaded or written to disk.
Credentials
okNo required environment variables, credentials, or config paths are declared or referenced. The docs mention external data sources (Bloomberg, FactSet) only as recommended sources, which is appropriate for the purpose.
Persistence & Privilege
okalways is false and the skill does not request system-wide persistence or modify other skills. Normal autonomous invocation is allowed by platform defaults but presents no additional red flags here.