Back to skill
Skillv1.0.0
ClawScan security
Goldman Sachs Group · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignApr 23, 2026, 8:07 PM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- This is an instruction-only, content-focused skill about Goldman Sachs that requests no binaries, credentials, or installs and its runtime instructions are consistent with the stated purpose.
- Guidance
- This skill is content-only and low-risk from a system/credential perspective. Before installing, consider: (1) source provenance — the skill lists no homepage and the publisher is unknown, so verify factual claims against reputable sources; (2) freshness and bias — financial summaries can become outdated quickly and may reflect author perspective; (3) citation needs — if you plan to rely on this for decisions, ask the skill (or its author) for sources or cross-check with official filings (SEC 10-K/10-Q) and reputable financial data providers. There are no technical red flags (no installs or credential requests).
Review Dimensions
- Purpose & Capability
- okThe skill's name and description are content/research-focused and the skill requires no binaries, env vars, or config paths — everything requested (nothing) is proportionate to a read-only informational skill.
- Instruction Scope
- okSKILL.md contains a research-oriented content template (history, business model, moat analysis) and a small read_when front-matter. It does not instruct the agent to read unrelated files, access environment variables, or transmit data to external endpoints.
- Install Mechanism
- okNo install spec or code files are present (instruction-only). Nothing will be written to disk or downloaded during install.
- Credentials
- okThe skill declares no environment variables, credentials, or config paths. There is no disproportionate credential request relative to the stated purpose.
- Persistence & Privilege
- okalways is false and the skill is user-invocable. The skill can be invoked autonomously by the agent (platform default) but that is not, by itself, a concern for this simple informational skill.
