Back to skill
Skillv1.0.0
ClawScan security
Asahi · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignApr 29, 2026, 1:06 PM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- This is a read-only informational skill about Asahi that contains static analysis text and does not request credentials, install software, or instruct the agent to access files or external services.
- Guidance
- This skill is an informational package and appears coherent with its stated purpose. Before relying on its figures or timeline in reports, verify important facts (dates, market share, revenue) against primary sources because SKILL.md has no citations. Also note the skill's publisher/homepage are not provided; if provenance or accountability matters for your use case, prefer a skill with an identifiable source or cross-check the content externally. Otherwise there are no security red flags (no installs, no credentials requested, no system access).
- Findings
[no_findings] expected: The regex-based scanner had no code to analyze because this is an instruction-only skill; absence of findings is expected but does not validate factual accuracy of the textual content.
Review Dimensions
- Purpose & Capability
- okThe skill's name and description (analyzing Asahi/Super Dry market impact and expansion) match the provided SKILL.md content. No extra binaries, env vars, or config paths are requested — proportions are appropriate for an informational skill.
- Instruction Scope
- noteSKILL.md is static content (timeline, business model, figures) rather than runtime instructions; it does not direct the agent to read system files, call external endpoints, or exfiltrate data. Note: the document makes factual claims without citations — consumers should verify data before using it in decisions.
- Install Mechanism
- okNo install spec or code files — lowest-risk instruction-only skill. Nothing will be written to disk or executed as part of installation.
- Credentials
- noteThe skill declares no required environment variables or credentials, which is proportionate. Minor provenance concern: source/homepage unknown and owner ID is opaque; that affects trust but not security posture.
- Persistence & Privilege
- okalways is false and autonomous invocation is allowed by platform default. The skill does not request persistent privileges or modify other skills or system configuration.
