Back to skill
Skillv1.0.0

ClawScan security

Corona Brand · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 23, 2026, 7:07 PM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
This is an instruction-only skill that provides static marketing/brand analysis about Corona beer and does not request credentials, install software, or instruct the agent to access unrelated files or systems.
Guidance
This skill appears low-risk: it is just a static knowledge/instruction file about Corona beer and does not install code or request secrets. Before installing, consider that the content may be out of date or simplified—if you need authoritative or current data (sales figures, legal ownership details, pandemic impact studies), verify with up-to-date primary sources. Also note the skill can be invoked by the agent (normal default); if you have strict autonomy policies, review or disable model/skill autonomous invocation in your agent configuration.

Review Dimensions

Purpose & Capability
okThe skill's name and description match the SKILL.md content: marketing/brand history and analysis of Corona. It does not declare unrelated capabilities or request unrelated resources.
Instruction Scope
okSKILL.md contains static content (timeline, analysis, data points) and 'read_when' triggers for when to use the text. It does not instruct the agent to read system files, access environment variables, run shell commands, or transmit data to external endpoints.
Install Mechanism
okThere is no install specification and no code files. Nothing is written to disk and no external packages are pulled in.
Credentials
okThe skill requires no environment variables, credentials, or config paths. No sensitive access is requested or implied.
Persistence & Privilege
okalways is false and the skill does not request persistent/system-wide changes. Model invocation is allowed (the default) but that is normal and not combined with any other high-risk permissions.