Back to skill
Skillv1.0.0
ClawScan security
Huawei Company · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignApr 26, 2026, 4:06 PM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- Informational skill about Huawei's history and sanctions response; it is instruction-only, requests no credentials or installs, and is internally consistent with its stated purpose.
- Guidance
- This skill appears to be a straightforward informational article about Huawei and does not pose direct security risks (no installs, no credentials). Before relying on its numbers or analysis, ask the skill for sources or citations and cross-check with up-to-date references — the SKILL.md contains static claims (employee count, revenue, patent share) that can become outdated or be rounded. If you plan to use the skill in automated workflows, note that autonomous invocation is allowed by default on the platform (normal behavior), but this skill's content-only nature means it cannot perform actions or access secrets. If you need more rigorous analysis, request source citations or a bibliography from the skill author.
Review Dimensions
- Purpose & Capability
- okThe name and description promise a narrative/analysis of Huawei's growth and sanction-era strategy; the skill contains only explanatory content and a short 'read_when' list relevant to that topic. No unrelated capabilities, credentials, or binaries are requested.
- Instruction Scope
- okSKILL.md is purely descriptive and sets topical triggers ('read_when') for when to use the content. It does not instruct the agent to access files, environment variables, external endpoints, or system resources beyond providing text, so its runtime instructions stay within the stated informational scope.
- Install Mechanism
- okThere is no install spec and no code files; this is the lowest-risk configuration because nothing is written to disk or fetched at install time.
- Credentials
- okThe skill requests no environment variables, credentials, or config paths. There is no disproportionate access requested relative to the simple informational purpose.
- Persistence & Privilege
- okalways is false and model invocation is the default (allowed) setting. The skill does not request persistent system presence or modify other skills' settings.
