Back to skill
Skillv1.0.0
ClawScan security
Capetown · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignApr 24, 2026, 9:03 AM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- This is an instruction-only, informational skill about Cape Town; it contains static city content in Chinese, requests no credentials or installs, and its behavior is consistent with its description.
- Guidance
- This skill is informational and low-risk: it only contains static content about Cape Town in Chinese and asks for no permissions. Before installing, consider whether you want the agent to automatically consult this localized content when you ask about the listed topics (the 'read_when' triggers). Also be aware the source is 'unknown' and there's no homepage—if you rely on this for critical decisions, verify facts against authoritative sources or request citations.
Review Dimensions
- Purpose & Capability
- okThe name, description, and SKILL.md all describe facts and analysis about Cape Town (history, economy, tourism, tech). There are no unrelated required binaries, env vars, or config paths — requirements align with an informational city skill.
- Instruction Scope
- okThe SKILL.md provides static content and a 'read_when' trigger list for when the agent should consult it. It does not instruct the agent to read local files, access environment variables, call external endpoints, or transmit data elsewhere.
- Install Mechanism
- okNo install spec and no code files are present. This is low-risk, instruction-only content that will not write or execute code on the host.
- Credentials
- okThe skill requires no environment variables, credentials, or config paths. There is no request for secrets or unrelated access.
- Persistence & Privilege
- okFlags are default (always:false) and the skill is user-invocable. It does not request permanent presence or system-level changes and does not modify other skills' configurations.
