Back to skill
Skillv1.0.0

ClawScan security

Kelloggs Cereal · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 30, 2026, 12:03 AM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
This is a read-only, informational skill about Kellogg's history and business; it requests no credentials, runs no installs or code, and its instructions contain only static content — overall coherent with its stated purpose.
Guidance
This skill is a static informational card about Kellogg's and appears low-risk: it asks for no credentials and has no install steps. However, the source/homepage is unknown — treat the content as unverified historical/business summary rather than authoritative. If you need actionable data (financials, legal use, or up-to-date figures), cross-check with official company filings, reputable news, or the companies' investor pages before relying on it.

Review Dimensions

Purpose & Capability
okThe skill name/description promise historical and business information about Kellogg's. The package contains only a SKILL.md with that content and requests no binaries, env vars, or config paths — all proportional to an informational skill.
Instruction Scope
okSKILL.md contains static content (summary, timeline, business model, data, 'read_when' guidance). It does not instruct the agent to run commands, access files, read environment variables, or transmit data to external endpoints.
Install Mechanism
okNo install spec and no code files are present. This instruction-only skill will not write files or download executables during install.
Credentials
okNo environment variables, credentials, or config paths are requested. The lack of secrets is appropriate for an informational skill.
Persistence & Privilege
okalways is false and the skill is user-invocable. It does not request elevated persistence or system-wide configuration changes.