Back to skill
Skillv1.0.0
ClawScan security
Carnegie Mellon · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignApr 24, 2026, 11:08 AM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- This is an instruction-only informational skill about Carnegie Mellon University; it requests no credentials, installs nothing, and its instructions are limited to presenting factual/descriptive content.
- Guidance
- This skill appears low-risk: it only provides informational content about Carnegie Mellon University and asks for nothing from your environment. Before relying on it for decisions (applications, funding figures, acceptance rates), verify key numbers and claims against authoritative sources (CMU website, US News, official reports) since the SKILL.md contains assertions that may be out-of-date or approximate. Because it is user-invocable and not always-on, it will not run unless you ask it to.
Review Dimensions
- Purpose & Capability
- okThe name, description, and SKILL.md all describe Carnegie Mellon University and related facts; there are no extra permissions, binaries, or credentials requested that would be unrelated to an informational skill.
- Instruction Scope
- okThe SKILL.md contains only summaries, timelines, strengths, and facts about CMU and includes a small set of read_when triggers; it does not instruct the agent to read system files, access environment variables, or transmit data externally.
- Install Mechanism
- okNo install specification and no code files are present (instruction-only), so nothing is written to disk or fetched during installation.
- Credentials
- okThe skill declares no required environment variables, credentials, or config paths — proportionate for a read-only informational skill.
- Persistence & Privilege
- okalways is false and the skill is user-invocable; model invocation is allowed (the platform default) but there is no elevated persistence or cross-skill configuration changes requested.
