Back to skill
Skillv1.0.0

ClawScan security

Asahi · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 29, 2026, 1:06 PM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
This is a read-only informational skill about Asahi that contains static analysis text and does not request credentials, install software, or instruct the agent to access files or external services.
Guidance
This skill is an informational package and appears coherent with its stated purpose. Before relying on its figures or timeline in reports, verify important facts (dates, market share, revenue) against primary sources because SKILL.md has no citations. Also note the skill's publisher/homepage are not provided; if provenance or accountability matters for your use case, prefer a skill with an identifiable source or cross-check the content externally. Otherwise there are no security red flags (no installs, no credentials requested, no system access).
Findings
[no_findings] expected: The regex-based scanner had no code to analyze because this is an instruction-only skill; absence of findings is expected but does not validate factual accuracy of the textual content.

Review Dimensions

Purpose & Capability
okThe skill's name and description (analyzing Asahi/Super Dry market impact and expansion) match the provided SKILL.md content. No extra binaries, env vars, or config paths are requested — proportions are appropriate for an informational skill.
Instruction Scope
noteSKILL.md is static content (timeline, business model, figures) rather than runtime instructions; it does not direct the agent to read system files, call external endpoints, or exfiltrate data. Note: the document makes factual claims without citations — consumers should verify data before using it in decisions.
Install Mechanism
okNo install spec or code files — lowest-risk instruction-only skill. Nothing will be written to disk or executed as part of installation.
Credentials
noteThe skill declares no required environment variables or credentials, which is proportionate. Minor provenance concern: source/homepage unknown and owner ID is opaque; that affects trust but not security posture.
Persistence & Privilege
okalways is false and autonomous invocation is allowed by platform default. The skill does not request persistent privileges or modify other skills or system configuration.