Back to skill
Skillv1.0.0
ClawScan security
Harvard University · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignApr 29, 2026, 10:06 PM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- This is an instruction-only informational skill about Harvard University that requests no credentials, performs no installs, and stays within its stated purpose — it appears internally consistent and low-risk.
- Guidance
- This skill is a read-only, instruction-only reference about Harvard University and does not request credentials or install software — that makes it low-risk from a security perspective. Before installing, consider: (1) content may be static or out-of-date (verify any facts you rely on, such as endowment or admission rates); (2) the SKILL.md is Chinese-language content — ensure language/locale matches your needs; (3) even benign informational skills can be used by an autonomous agent to produce output, so review agent invocation policies if you restrict autonomous actions. No technical credentials or filesystem access are requested, so there are no direct exfiltration concerns.
Review Dimensions
- Purpose & Capability
- okName, description, and SKILL.md all describe an informational/reference skill about Harvard University. The skill declares no binaries, env vars, or config paths, which is proportionate to an encyclopedia-style skill.
- Instruction Scope
- okSKILL.md contains descriptive content and a short 'read_when' list specifying scenarios where the content should be used. It does not instruct the agent to read arbitrary files, access environment variables, call external endpoints, or transmit data—scope remains limited to providing background and facts about Harvard.
- Install Mechanism
- okNo install specification or code files are present. Because this is instruction-only, nothing is written to disk or installed—this is the lowest-risk install posture.
- Credentials
- okThe skill requires no environment variables, credentials, or config paths. There are no opaque secret requests; requested capabilities are proportional to an informational skill.
- Persistence & Privilege
- okalways is false and model invocation is allowed (the default). There is no evidence the skill requests permanent presence, modifies other skills, or accesses other skills' credentials.
