Back to skill
Skillv1.0.0

ClawScan security

Amsterdam City · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 29, 2026, 9:05 PM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
This is an instruction-only, Chinese-language encyclopedia skill about Amsterdam; it requests no credentials, installs nothing, and its instructions are limited to providing factual content — the pieces are internally coherent.
Guidance
This skill is essentially a static encyclopedia entry about Amsterdam and appears safe to install from a security perspective: it asks for no credentials, installs nothing, and its instructions are limited to content use. Consider these practical points before installing: (1) the factual claims (GDP, population, visitor counts, historical assertions) are approximate — verify against authoritative sources if you need accuracy; (2) the skill is Chinese-language — if you need another language, request/translate accordingly; (3) the agent can still invoke the skill autonomously by default (normal behavior); if you prefer to restrict autonomous use, disable model invocation or configure agent permissions. Overall there are no security red flags in the provided files.

Review Dimensions

Purpose & Capability
okName, description, and SKILL.md all describe the same purpose (encyclopedic city guide). The skill requests no binaries, env vars, or config paths, which is proportionate to an informational skill.
Instruction Scope
okSKILL.md contains static content and 'read_when' triggers describing when to use the content. It does not instruct the agent to read local files, access other services, exfiltrate data, or call external endpoints.
Install Mechanism
okNo install spec and no code files are present (instruction-only). Nothing is written to disk or downloaded during install.
Credentials
okThe skill declares no required environment variables or credentials; there are no hidden requests for secrets in the instructions.
Persistence & Privilege
okalways is false and disable-model-invocation is default (agent may invoke autonomously), which is normal and not excessive for this type of skill.