Back to skill
Skillv1.0.0

ClawScan security

Breguet · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 24, 2026, 11:07 AM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
The skill is an instruction-only informational bundle about the Breguet watch brand; its requested resources and runtime instructions are proportional to that purpose and contain no surprising or unrelated requirements.
Guidance
This skill is low-risk and simply provides an informational summary of Breguet in Chinese. Before installing, note that it contains no citations or external sources — verify critical facts independently if you need authoritative references. Because it is instruction-only (no installers, no required credentials), it does not introduce obvious privilege or credential risks. If you expect up-to-date figures or primary sources, request a version that includes citations or links to official materials.
Findings
[no-findings] expected: The regex-based scanner had nothing to analyze because this is an instruction-only skill with no code files; that absence is expected for a static informational skill.

Review Dimensions

Purpose & Capability
okName, description and SKILL.md all describe historical and product information about Breguet; nothing in the package requests unrelated credentials, binaries, or config paths.
Instruction Scope
okSKILL.md contains static content and a small 'read_when' guidance list in Chinese about when to consult the skill (research history, analyze tourbillon, etc.). It does not instruct reading system files, accessing environment variables, calling external endpoints, or transmitting data.
Install Mechanism
okNo install spec and no code files — instruction-only skills have minimal attack surface because they add no binaries or installers.
Credentials
okThe skill declares no required environment variables, credentials, or config paths; this matches its simple informational purpose.
Persistence & Privilege
okalways is false and there is no indication the skill attempts to persist, modify other skills, or require elevated/system-wide privileges.