Back to skill
Skillv1.0.0

ClawScan security

Harvard University · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 29, 2026, 10:06 PM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
This is an instruction-only informational skill about Harvard University that requests no credentials, performs no installs, and stays within its stated purpose — it appears internally consistent and low-risk.
Guidance
This skill is a read-only, instruction-only reference about Harvard University and does not request credentials or install software — that makes it low-risk from a security perspective. Before installing, consider: (1) content may be static or out-of-date (verify any facts you rely on, such as endowment or admission rates); (2) the SKILL.md is Chinese-language content — ensure language/locale matches your needs; (3) even benign informational skills can be used by an autonomous agent to produce output, so review agent invocation policies if you restrict autonomous actions. No technical credentials or filesystem access are requested, so there are no direct exfiltration concerns.

Review Dimensions

Purpose & Capability
okName, description, and SKILL.md all describe an informational/reference skill about Harvard University. The skill declares no binaries, env vars, or config paths, which is proportionate to an encyclopedia-style skill.
Instruction Scope
okSKILL.md contains descriptive content and a short 'read_when' list specifying scenarios where the content should be used. It does not instruct the agent to read arbitrary files, access environment variables, call external endpoints, or transmit data—scope remains limited to providing background and facts about Harvard.
Install Mechanism
okNo install specification or code files are present. Because this is instruction-only, nothing is written to disk or installed—this is the lowest-risk install posture.
Credentials
okThe skill requires no environment variables, credentials, or config paths. There are no opaque secret requests; requested capabilities are proportional to an informational skill.
Persistence & Privilege
okalways is false and model invocation is allowed (the default). There is no evidence the skill requests permanent presence, modifies other skills, or accesses other skills' credentials.