Back to skill
Skillv1.0.0

ClawScan security

Breguet Alt · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 24, 2026, 5:10 PM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
This is an instruction-only skill that provides historical and commercial information about Breguet watches and does not request credentials, install software, or access system resources—its declared capabilities match its requirements.
Guidance
This skill appears coherent and low-risk from a security perspective: it is an instruction-only content skill about Breguet watches and asks for no permissions. Before installing, consider that the SKILL.md source is 'unknown' and there are no citations—if you rely on the historical or commercial figures in critical contexts, verify them against authoritative sources. If you are concerned about autonomous invocation, note the skill can be invoked by the agent (disable-model-invocation is false) but it does not require special privileges or credentials.

Review Dimensions

Purpose & Capability
okSkill name and description describe historical/market analysis of the Breguet brand; the skill declares no binaries, env vars, or config paths. The requested surface (none) is proportionate to the stated purpose.
Instruction Scope
okSKILL.md contains prose (history, timeline, analysis) and 'read_when' triggers. It does not instruct the agent to read arbitrary files, access environment variables, call external endpoints, or perform actions beyond producing content about the brand. No scope creep detected.
Install Mechanism
okThere is no install specification and no code files. This is the lowest-risk arrangement—nothing will be written to disk or executed by an installer.
Credentials
okThe skill requires no environment variables, credentials, or config paths. No disproportionate access to secrets or unrelated services is requested.
Persistence & Privilege
okalways is false and the skill is user-invocable. disable-model-invocation is false (normal), but the skill does not request persistent presence, system changes, or modification of other skills/configs.