Back to skill
Skillv1.0.0

ClawScan security

Blackrock Investments · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 29, 2026, 9:05 PM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
This is an instruction-only, read-only knowledge brief about BlackRock/Aladdin; it requests no credentials, no installs, and its content matches its name and description.
Guidance
This skill is a static informational briefing about BlackRock and its Aladdin platform and appears low-risk: it requests no credentials, installs, or file access. Consider whether you trust the source for factual accuracy and potential bias (no homepage or known publisher is provided). If you need up-to-date or authoritative data for financial decisions, cross-check with primary sources (company filings, reputable news, or official BlackRock publications) before acting on the content.

Review Dimensions

Purpose & Capability
okThe skill is a factual/analytical briefing on BlackRock and Aladdin. Its name, description, and SKILL.md content are consistent and it does not request unrelated capabilities, binaries, or credentials.
Instruction Scope
okSKILL.md contains only explanatory sections (summary, timeline, analysis, read_when). It does not instruct the agent to read local files, access environment variables, call external endpoints, or perform actions outside producing informational responses.
Install Mechanism
okNo install spec and no code files are present. Being instruction-only means nothing is written to disk and no external packages are pulled in.
Credentials
okThe skill declares no required environment variables, no credentials, and no config paths — appropriate for a read-only briefing skill.
Persistence & Privilege
okalways is false and the skill does not request persistent or elevated privileges. Autonomous model invocation is allowed by default on the platform but the skill itself does not gain extra privilege.