Back to skill
Skillv1.0.0
ClawScan security
Flipkart · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignApr 19, 2026, 1:14 AM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- This is an instruction-only informational skill about Flipkart; it only provides static content and read triggers and does not request credentials, install code, or perform any actions outside its stated purpose.
- Guidance
- This skill is an informational summary about Flipkart and appears coherent and low-risk (no credentials, no installs, no file access). The source is listed as 'unknown' and there is no homepage or citations — if you plan to act on the facts (investment, business decisions, etc.), verify key claims against authoritative sources. If you prefer to prevent automatic invocation, you can disable or remove the skill; otherwise it will only run when triggered by relevant queries.
Review Dimensions
- Purpose & Capability
- okThe skill name and description (Flipkart company overview) match the SKILL.md content: historical timeline, business analysis, and key metrics. Nothing requested (no env vars, binaries, or config paths) is unrelated to providing an informational summary.
- Instruction Scope
- okThe SKILL.md contains only read/serve-style instructions and a 'read_when' trigger list (when the user queries Flipkart or related topics). It does not instruct the agent to read local files, access environment variables, call external endpoints, or transmit data elsewhere.
- Install Mechanism
- okNo install spec and no code files are present. This instruction-only skill writes nothing to disk and does not pull external code — lowest-risk install profile.
- Credentials
- okThe skill requests no environment variables, credentials, or config paths. There is no disproportionate access requested for the skill's stated informational purpose.
- Persistence & Privilege
- okalways is false and the skill is user-invocable. The skill does not request permanent presence or modify other skills or system-wide settings. The agent's ability to invoke the skill autonomously is the platform default and not a red flag here.
