Back to skill
Skillv1.0.0

ClawScan security

Capetown · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 24, 2026, 9:03 AM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
This is an instruction-only, informational skill about Cape Town; it contains static city content in Chinese, requests no credentials or installs, and its behavior is consistent with its description.
Guidance
This skill is informational and low-risk: it only contains static content about Cape Town in Chinese and asks for no permissions. Before installing, consider whether you want the agent to automatically consult this localized content when you ask about the listed topics (the 'read_when' triggers). Also be aware the source is 'unknown' and there's no homepage—if you rely on this for critical decisions, verify facts against authoritative sources or request citations.

Review Dimensions

Purpose & Capability
okThe name, description, and SKILL.md all describe facts and analysis about Cape Town (history, economy, tourism, tech). There are no unrelated required binaries, env vars, or config paths — requirements align with an informational city skill.
Instruction Scope
okThe SKILL.md provides static content and a 'read_when' trigger list for when the agent should consult it. It does not instruct the agent to read local files, access environment variables, call external endpoints, or transmit data elsewhere.
Install Mechanism
okNo install spec and no code files are present. This is low-risk, instruction-only content that will not write or execute code on the host.
Credentials
okThe skill requires no environment variables, credentials, or config paths. There is no request for secrets or unrelated access.
Persistence & Privilege
okFlags are default (always:false) and the skill is user-invocable. It does not request permanent presence or system-level changes and does not modify other skills' configurations.