Back to skill
Skillv1.0.1

ClawScan security

Pricing · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 14, 2026, 3:09 AM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
This is a coherent, instruction-only pricing adviser that asks for no credentials, installs nothing, and stays within its stated purpose.
Guidance
This skill is low-risk: it only provides pricing advice and asks you questions to compute prices. Before sharing sensitive business or customer data with the skill, review privacy concerns — the skill itself does not request credentials or external network calls, but any data you paste into a chat could be exposed to the model. Also remember its recommendations are heuristic; verify legal/regulatory constraints and validate pricing decisions with market testing and your own calculations.

Review Dimensions

Purpose & Capability
okName, description, and runtime instructions all describe a pricing advisor; there are no unrelated requirements (no env vars, binaries, or installs).
Instruction Scope
okSKILL.md contains guidance, questions to ask the user, and calculational prompts only. It does not instruct the agent to read files, access environment variables, call external endpoints, or exfiltrate data.
Install Mechanism
okNo install spec or code files are present (instruction-only), so nothing will be downloaded or written to disk during installation.
Credentials
okThe skill requires no credentials, no config paths, and does not request sensitive environment variables — appropriate for a purely advisory skill.
Persistence & Privilege
okalways is false and the skill is user-invocable. It does not request persistent system presence or modify other skills/configs.