Back to skill
Skillv1.0.0

ClawScan security

Alexander Mcqueen · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 28, 2026, 9:02 PM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
This is an instruction-only, content/reference skill about Alexander McQueen that does not request credentials, binaries, or installs and its behavior aligns with its stated purpose.
Guidance
This skill is content-only and low risk: it neither installs software nor requests credentials. Before installing, consider whether you need sourced or citable references (the SKILL.md is an unsourced narrative—verify facts if you require academic or legal accuracy). If you expect the skill to fetch live data (news, current staff, or sales figures), note that this SKILL.md contains static text and does not describe any external data fetching. Review updates to the SKILL.md in the future in case runtime behavior changes.

Review Dimensions

Purpose & Capability
okThe name/description (a comprehensive reference on Alexander McQueen) matches the SKILL.md content: encyclopedic fashion history, timelines, runway descriptions, and business context. There are no unexpected requirements (no env vars, binaries, or config paths).
Instruction Scope
okSKILL.md is purely informational and the 'read_when' triggers are topical (fashion research). The instructions do not direct the agent to read system files, access environment variables, call external endpoints, collect or transmit user data, or perform actions outside providing reference content.
Install Mechanism
okNo install spec and no code files are present. Because this is instruction-only, nothing is written to disk or installed at runtime — lowest-risk installation model.
Credentials
okThe skill requests no environment variables, credentials, or config paths. The lack of secrets or unrelated credentials is proportionate to its stated informational purpose.
Persistence & Privilege
okFlags are default (always: false, user-invocable true, model invocation allowed). The skill does not request permanent presence or system-wide config changes; autonomy is the platform default and presents no additional risk given the skill's content-only nature.