Back to skill
Skillv1.0.0

ClawScan security

Goldman Sachs Bank · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 30, 2026, 12:03 AM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
This is an instruction-only informational skill (a Chinese-language profile of Goldman Sachs) that does not request credentials, install software, or instruct the agent to access system files or external endpoints, and is internally consistent with its stated purpose.
Guidance
This skill appears to be a safe, read-only informational summary about Goldman Sachs. Before installing, note that the skill has no declared source or homepage and the owner is unknown — the content may be a static snapshot, incomplete, or inaccurate. If you plan to rely on this for decisions, verify facts against authoritative sources. Because it requests no credentials and performs no I/O, there is no direct security risk from installing it, but treat its factual claims as unverified and avoid providing any private data to the skill.

Review Dimensions

Purpose & Capability
okThe name/description claim a Goldman Sachs profile and the SKILL.md contains historical, business-model, and analysis content about Goldman Sachs. There are no unrelated requirements (no env vars, binaries, or config paths), so requested capabilities match the stated purpose.
Instruction Scope
okSKILL.md is static content / documentation. It does not instruct the agent to run shell commands, read system files, access environment variables, call external endpoints, or transmit data. The scope is limited to presenting informational text about Goldman Sachs.
Install Mechanism
okThere is no install specification and no code files. Because this is instruction-only, nothing is written to disk and there is no install-time risk.
Credentials
okThe skill declares no required environment variables, credentials, or config paths. It does not request secrets or other sensitive access, which is proportionate for a read-only informational skill.
Persistence & Privilege
okFlags show the skill is user-invocable and not always-enabled. It does not request permanent presence or elevated privileges and does not modify other skills or system settings.