Back to skill
Skillv1.0.0

ClawScan security

Conocophillips · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 25, 2026, 3:06 PM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
This skill is a static, instruction-only knowledge card about ConocoPhillips; it requests no credentials, installs nothing, and its contents match its stated purpose.
Guidance
This is a read-only informational skill about ConocoPhillips with no network, install, or credential requirements — low risk. Before installing, note that the source/homepage is unknown and the content is static: verify any time-sensitive numbers (revenue, production, deals) against authoritative sources if you need up-to-date data. If you expect live stock prices or real-time production metrics, this skill won't provide them. Otherwise it's safe and coherent with its stated purpose.

Review Dimensions

Purpose & Capability
okName and description (ConocoPhillips company profile) match the SKILL.md content (historical timeline, business model, metrics, analysis). No extra capabilities or unrelated requirements are declared.
Instruction Scope
okSKILL.md is purely informational and lists 'read_when' triggers for context. It does not instruct the agent to read files, access environment variables, call external endpoints, or transmit data.
Install Mechanism
okNo install spec, no code files that execute, and no downloads — instruction-only skills are lowest-risk in install mechanism.
Credentials
okThe skill declares no required environment variables, credentials, or config paths. There are no unexplained secret requests.
Persistence & Privilege
okalways is false and the skill does not request persistent system presence or modify other skills. It is user-invocable and may be called autonomously by the agent (platform default), which is reasonable for an informational skill.