Back to skill
Skillv1.0.0

ClawScan security

Candylab · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 28, 2026, 10:04 AM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
This is an instruction-only informational skill about the Candylab toy brand; it requests no credentials, performs no installs, and its content is limited to brand/history/market notes.
Guidance
This skill is a simple static info page about the Candylab brand and appears internally consistent and low-risk. Before relying on specific claims (founding dates, sales figures, retail partners), verify them against authoritative sources because SKILL.md contains unsourced assertions and could be outdated or partially fabricated. No credentials or installs are required, but if you plan to act on its business data (e.g., for purchasing, reporting, or investment decisions), cross-check with primary sources.

Review Dimensions

Purpose & Capability
okThe name/description (Candylab toys, Nordic design, Montessori/market analysis) match the SKILL.md content; nothing in the skill requests unrelated resources or capabilities.
Instruction Scope
okSKILL.md contains static informational content and read_when triggers for when to present it. It does not instruct the agent to read files, access environment variables, run commands, or transmit data externally.
Install Mechanism
okThere is no install specification and no code files; the skill is instruction-only, so nothing will be written to disk or downloaded during install.
Credentials
okThe skill declares no required environment variables, credentials, or config paths, which is appropriate for a read-only informational skill.
Persistence & Privilege
okalways is false and model invocation is allowed (the platform default). The skill does not request elevated persistence or modify other skills or system settings.