Back to skill
Skillv1.0.0
ClawScan security
Kkr · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignApr 28, 2026, 6:04 PM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- This is a read-only, instruction-only informational skill about KKR that requests no credentials, binaries, or installs — its footprint matches its stated purpose and appears low risk.
- Guidance
- This skill is informational and low-risk: it won't access your files or credentials. Consider that the content is static and may become outdated or simplified; if you need authoritative or current financial data (AUM, fund performance, recent transactions), verify against primary sources (KKR filings, SEC, reputable financial news). If you require automated data retrieval or actions (e.g., pulling live filings), prefer a skill that explicitly requests the necessary API credentials and documents its external calls.
Review Dimensions
- Purpose & Capability
- okThe skill name, description, and SKILL.md all present the same purpose (historical and business analysis of KKR). It declares no dependencies, env vars, or installs, which is proportionate for an informational skill.
- Instruction Scope
- okSKILL.md contains static content and a short 'read_when' trigger list; it does not instruct the agent to read local files, access environment variables, call external endpoints, or perform actions outside of providing information about KKR.
- Install Mechanism
- okNo install spec or code files are present. As an instruction-only skill, nothing is written to disk or installed, which is consistent with its purpose and lowest-risk.
- Credentials
- okThe skill requires no environment variables, credentials, or config paths. There is no request for secrets or unrelated access that would be disproportionate for its stated function.
- Persistence & Privilege
- okFlags show standard behavior (user-invocable, not always-installed, model invocation enabled). There is no indication the skill attempts to persist or escalate privileges.
