Back to skill
Skillv1.0.0

ClawScan security

Nano Banana Kling Ad Workflow · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignFeb 11, 2026, 9:31 AM
Verdict
Benign
Confidence
high
Model
gpt-5-mini
Summary
This skill is an instruction-only checklist for creating ads with Nano Banana and Kling 3.0; its requirements and instructions are consistent with that purpose and it does not request unexplained credentials or install code.
Guidance
This is an instruction-only workflow checklist and is internally coherent. Because the skill's source and homepage are unknown, consider the following before installing or using it: (1) at runtime you or your agent will likely need Nano Banana and Kling API credentials—provide those only if you trust the integration and understand costs; (2) confirm any provider Terms of Service, credit costs, and content/licensing implications (especially for likeness/voice use); (3) be cautious about feeding sensitive data into generation prompts; and (4) if you want higher assurance, ask the publisher for provenance (homepage, author) or prefer a skill with a known source. Overall risk is low for this instruction-only checklist, but verify external service credentials and costs when you actually run the pipeline.

Review Dimensions

Purpose & Capability
okThe name/description match the instructions: a two-stage Nano Banana (image) → Kling 3.0 (video) ad pipeline. No unrelated binaries, env vars, or config paths are requested, so the declared capabilities align with what the skill actually asks the agent to do.
Instruction Scope
okSKILL.md stays within the ad-production workflow: shot planning, prompt patterns, generation/animation steps, cost-tracking and deliverables. It does not instruct reading system files, other skills' configs, or exporting data to unexpected endpoints. The only minor openness: it says 'If missing, ask for only the minimum required details and proceed,' which grants some discretion but is reasonable for a production checklist.
Install Mechanism
okNo install specification or code files are present (instruction-only). There is nothing written to disk or fetched at install time, which minimizes supply-chain risk.
Credentials
okThe skill does not require environment variables, API keys, or credentials in its metadata. That is proportionate: the workflow describes third-party services (Nano Banana, Kling) but does not ask for unrelated secrets. Note: actual runtime use with those services would typically require API keys, but those are not requested by this skill itself.
Persistence & Privilege
okalways is false and the skill is user-invocable; it does not request persistent or elevated privileges nor does it modify other skills or system-wide settings.