Back to skill
Skillv1.0.0

ClawScan security

Coca Cola Corp · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 23, 2026, 7:06 PM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
This is an instruction-only informational skill about Coca‑Cola's business and brand strategy; it requests no credentials, installs nothing, and its runtime instructions are purely descriptive.
Guidance
This skill appears to be a static knowledge doc about The Coca‑Cola Company and is internally consistent and low-risk: it asks for no secrets and installs nothing. Before relying on its facts for important decisions, verify key data (financial figures, dates, percentages) against primary sources because the SKILL.md provides assertions without citations. Also be cautious if a later version adds install steps or environment-variable requirements — that would change the risk profile.

Review Dimensions

Purpose & Capability
okThe name/description (Coca‑Cola franchise and brand analysis) matches the SKILL.md content. There are no unrelated requirements (no env vars, binaries, or installs) that would be inconsistent with an informational/reference skill.
Instruction Scope
okSKILL.md is purely authoring/knowledge content and 'read_when' metadata showing when to use it. It contains no commands, file reads, or directives to access environment variables or external endpoints beyond its descriptive text.
Install Mechanism
okNo install spec and no code files are provided (instruction-only). That presents minimal surface area — nothing is downloaded or written to disk by the skill itself.
Credentials
okThe skill declares no required environment variables, credentials, or config paths. There is nothing disproportionate or unrelated requested for the stated informational purpose.
Persistence & Privilege
okFlags are default (always: false, agent invocation allowed). The skill does not request permanent presence or elevated privileges and does not modify other skills or system-wide settings.