Back to skill
Skillv1.0.0
ClawScan security
Cambridge University · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignApr 29, 2026, 7:03 PM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- This is a content-only skill providing encyclopedic information about the University of Cambridge; it requests no credentials, installs, or system access and is internally consistent with its stated purpose.
- Guidance
- This skill is a read-only, instruction-only content pack about Cambridge University and does not request system access or secrets, so its risk is low. Consider the following before installing: (1) the source is listed as unknown — verify the publisher if provenance matters to you; (2) content accuracy may vary, so cross-check facts before relying on them for decisions; (3) although benign, any skill can present misinformation or bias, so treat outputs as informational rather than authoritative.
Review Dimensions
- Purpose & Capability
- okName/description (historical/encyclopedic information about Cambridge) matches the SKILL.md content; there are no unexpected required binaries, env vars, or config paths.
- Instruction Scope
- okSKILL.md contains only topical guidance (when to read/use the content) and encyclopedic text about the university; it does not instruct the agent to read files, access other services, or transmit data externally.
- Install Mechanism
- okThere is no install spec and no code files. Because this is instruction-only, nothing will be written to disk or executed during install.
- Credentials
- okThe skill declares no environment variables, credentials, or config paths. No sensitive access is requested and none appears necessary for the stated purpose.
- Persistence & Privilege
- okDefaults are used (not always:true). The skill is user-invocable and may be called autonomously by the agent (platform default), which is appropriate for a content skill and does not add special privileges.
