Back to skill
Skillv1.0.0

ClawScan security

Ab Inbev · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 23, 2026, 1:02 PM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
This is an instruction-only, read-only informational skill about AB InBev; its contents and requested capabilities are consistent with the name and description and it requests no credentials or installs.
Guidance
This skill is a static informational document about AB InBev and appears coherent and low-risk: it asks for no credentials and installs nothing. Consider the following before installing: (1) provenance — the source/owner is unknown and there is no homepage, so verify facts if you need authoritative or up-to-date data; (2) functionality — this skill provides static content only (no live data or integrations); (3) agent behavior — although harmless, the agent may include the skill's text in responses, so check outputs for accuracy. If you require verified financial or legal data, use an official or cited source instead.

Review Dimensions

Purpose & Capability
noteThe skill's name, description, and SKILL.md content all describe an AB InBev company overview and related analysis — the requested surface (none) matches that purpose. Note: the skill has no homepage or trusted source metadata, so provenance and freshness of the information are unknown.
Instruction Scope
okSKILL.md contains static guidance and a reading cue list; it does not instruct the agent to read local files, access environment variables, call external endpoints, or exfiltrate data.
Install Mechanism
okNo install spec or code files are present (instruction-only), so nothing is written to disk and no third-party packages are fetched.
Credentials
okThe skill requests no environment variables, credentials, or config paths — proportional and minimal for an informational skill.
Persistence & Privilege
okalways is false and the skill does not request persistent/system-level privileges. It is user-invocable and can be called autonomously per platform defaults.