Back to skill
Skillv1.0.0
ClawScan security
Founder · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignApr 7, 2026, 12:20 AM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- The skill is an instruction-only ‘founder’ consultant that contains reference docs and guidance consistent with its stated purpose and requests no extra privileges or installs.
- Guidance
- This skill appears coherent and low-risk: it provides startup frameworks, templates, and curated references without requesting credentials or installing code. Before installing, consider: (1) provenance — the source/homepage is unknown, so verify advice or sensitive numbers against primary references; (2) privacy — don’t paste proprietary secrets, financial statements, or private investor data into prompts you don’t want shared; (3) invocation behavior — it will activate on keyword triggers described in SKILL.md, so disable autonomous invocation if you prefer only manual use; and (4) legal/financial limits — treat recommendations as general guidance, not professional legal/accounting advice.
Review Dimensions
- Purpose & Capability
- okName/description (founder/startup consultant) align with the included SKILL.md and reference files (fundraising, growth, tools). The skill requests no binaries, env vars, or config paths that would be unnecessary for giving business advice.
- Instruction Scope
- okRuntime instructions are limited to providing frameworks, structured templates, and consulting advice and explicitly reference the included static reference files. The SKILL.md does not instruct the agent to read system files, access environment variables, call external endpoints, or exfiltrate data.
- Install Mechanism
- okNo install spec and no code files — the skill is instruction-only. This minimizes filesystem/network risk because nothing is downloaded or executed by the skill itself.
- Credentials
- okThe skill declares no required environment variables, credentials, or config paths. That is proportionate to a knowledge/consulting skill that only serves static reference material and guidance.
- Persistence & Privilege
- okalways is false and the skill does not request persistent, system-level privileges or modify other skills' configs. Autonomous invocation is allowed (platform default) but not combined with other concerning privileges.
