Back to skill
Skillv1.0.0

ClawScan security

Lisbon City · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 28, 2026, 10:05 PM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
This is a read-only, instruction-only informational skill about Lisbon whose declared purpose and runtime instructions align and which requests no installs, credentials, or system access.
Guidance
This skill appears safe from a security/access perspective because it is read-only and requests no installs or secrets. However, the publisher/source and homepage are missing—treat factual claims as unverified and cross-check any critical facts (dates, statistics, policy claims) against trusted sources before relying on them. If you plan to allow autonomous agent use, note that the agent may cite this content when relevant but it cannot access your system or credentials via this skill.

Review Dimensions

Purpose & Capability
okName/description match the SKILL.md content about Lisbon (history, urban resilience, tech scene). The skill declares no extra capabilities or resources, so nothing appears out of scope for an informational city guide.
Instruction Scope
okSKILL.md is static content with a summary and narrow 'read_when' triggers (research contexts). It does not instruct the agent to read files, access environment variables, call external endpoints, or collect unrelated data.
Install Mechanism
okNo install spec and no code files are present (instruction-only). Nothing is written to disk or downloaded during install.
Credentials
okThe skill requires no environment variables, credentials, or config paths. No sensitive access is requested.
Persistence & Privilege
okalways is false and the skill does not request elevated or persistent system privileges. Autonomous invocation is allowed (platform default) but the skill's scope is read-only informational.