Back to skill
Skillv1.0.0

ClawScan security

Byd Ev · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 29, 2026, 9:06 PM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
This is an instruction-only informational skill about BYD (比亚迪) that requests no credentials, installs, or special permissions and its content matches its name and description.
Guidance
This skill is an informational summary and appears internally consistent and low-risk: it asks for nothing and contains only static content. However, the package has an unknown source and no homepage, so you cannot independently verify the author — consider: (1) treat the content as informational rather than authoritative and cross-check important facts, (2) only enable autonomous invocation if you trust the skill source (it currently can be invoked by the agent, which is the platform default), and (3) prefer skills from verifiable publishers if you need reliable or sensitive workflows.

Review Dimensions

Purpose & Capability
okThe skill is a factual/analytical write-up about BYD. There are no required binaries, env vars, or config paths and nothing requested that would be unrelated to an informational reference.
Instruction Scope
okSKILL.md only contains descriptive text, timeline, analysis and use-cases for reading; it does not instruct the agent to read files, access credentials, or transmit data to external endpoints.
Install Mechanism
okNo install spec and no code files are present, so nothing is written to disk or fetched at installation time.
Credentials
okThe skill declares no environment variables, credentials, or config paths—there is no disproportionate access requested.
Persistence & Privilege
okalways is false and the skill does not request elevated persistence or to modify other skills; model invocation is allowed (the platform default) but the skill has no capabilities that would abuse that autonomy.