Back to skill
Skillv1.0.0
ClawScan security
Candylab · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignApr 28, 2026, 10:04 AM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- This is an instruction-only informational skill about the Candylab toy brand; it requests no credentials, performs no installs, and its content is limited to brand/history/market notes.
- Guidance
- This skill is a simple static info page about the Candylab brand and appears internally consistent and low-risk. Before relying on specific claims (founding dates, sales figures, retail partners), verify them against authoritative sources because SKILL.md contains unsourced assertions and could be outdated or partially fabricated. No credentials or installs are required, but if you plan to act on its business data (e.g., for purchasing, reporting, or investment decisions), cross-check with primary sources.
Review Dimensions
- Purpose & Capability
- okThe name/description (Candylab toys, Nordic design, Montessori/market analysis) match the SKILL.md content; nothing in the skill requests unrelated resources or capabilities.
- Instruction Scope
- okSKILL.md contains static informational content and read_when triggers for when to present it. It does not instruct the agent to read files, access environment variables, run commands, or transmit data externally.
- Install Mechanism
- okThere is no install specification and no code files; the skill is instruction-only, so nothing will be written to disk or downloaded during install.
- Credentials
- okThe skill declares no required environment variables, credentials, or config paths, which is appropriate for a read-only informational skill.
- Persistence & Privilege
- okalways is false and model invocation is allowed (the platform default). The skill does not request elevated persistence or modify other skills or system settings.
