Back to skill
Skillv1.0.0

ClawScan security

Corning · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 23, 2026, 7:07 PM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
This is an instruction-only informational briefing about Corning (history, products, market position) and it does not request credentials, install code, or instruct the agent to access system resources.
Guidance
This skill is a read-only briefing and appears internally consistent. Before relying on figures or historical claims for decisions, cross-check them against primary sources (investor reports, company filings, or trusted histories) since SKILL.md may contain simplifications or minor inaccuracies. If you prefer to limit automatic use of skills, you can disable autonomous invocation for skills in your agent settings; otherwise this skill poses minimal risk because it requests no credentials or installs.

Review Dimensions

Purpose & Capability
okThe skill name, description, and SKILL.md all describe the same purpose: an expert briefing about Corning and its glass technologies. There are no unrelated required binaries, env vars, or config paths.
Instruction Scope
okSKILL.md contains static content (timeline, business analysis, facts) and 'read_when' triggers for when to use the briefing. It does not instruct the agent to read files, access environment variables, call external endpoints, or collect/transmit system data.
Install Mechanism
okNo install spec and no code files are present; this is instruction-only, which is the lowest install risk (nothing is written to disk or executed).
Credentials
okThe skill declares no required environment variables, credentials, or config paths. It does not request any sensitive tokens or system-level access.
Persistence & Privilege
okalways is false (no forced inclusion). Model invocation is allowed (default) but that is normal for skills and acceptable here because the skill does not request elevated privileges or secrets.