Back to skill
Skillv1.0.0

ClawScan security

Founder · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 7, 2026, 12:20 AM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
The skill is an instruction-only ‘founder’ consultant that contains reference docs and guidance consistent with its stated purpose and requests no extra privileges or installs.
Guidance
This skill appears coherent and low-risk: it provides startup frameworks, templates, and curated references without requesting credentials or installing code. Before installing, consider: (1) provenance — the source/homepage is unknown, so verify advice or sensitive numbers against primary references; (2) privacy — don’t paste proprietary secrets, financial statements, or private investor data into prompts you don’t want shared; (3) invocation behavior — it will activate on keyword triggers described in SKILL.md, so disable autonomous invocation if you prefer only manual use; and (4) legal/financial limits — treat recommendations as general guidance, not professional legal/accounting advice.

Review Dimensions

Purpose & Capability
okName/description (founder/startup consultant) align with the included SKILL.md and reference files (fundraising, growth, tools). The skill requests no binaries, env vars, or config paths that would be unnecessary for giving business advice.
Instruction Scope
okRuntime instructions are limited to providing frameworks, structured templates, and consulting advice and explicitly reference the included static reference files. The SKILL.md does not instruct the agent to read system files, access environment variables, call external endpoints, or exfiltrate data.
Install Mechanism
okNo install spec and no code files — the skill is instruction-only. This minimizes filesystem/network risk because nothing is downloaded or executed by the skill itself.
Credentials
okThe skill declares no required environment variables, credentials, or config paths. That is proportionate to a knowledge/consulting skill that only serves static reference material and guidance.
Persistence & Privilege
okalways is false and the skill does not request persistent, system-level privileges or modify other skills' configs. Autonomous invocation is allowed (platform default) but not combined with other concerning privileges.