Back to skill
Skillv1.0.0
ClawScan security
Lisbon City · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignApr 28, 2026, 10:05 PM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- This is a read-only, instruction-only informational skill about Lisbon whose declared purpose and runtime instructions align and which requests no installs, credentials, or system access.
- Guidance
- This skill appears safe from a security/access perspective because it is read-only and requests no installs or secrets. However, the publisher/source and homepage are missing—treat factual claims as unverified and cross-check any critical facts (dates, statistics, policy claims) against trusted sources before relying on them. If you plan to allow autonomous agent use, note that the agent may cite this content when relevant but it cannot access your system or credentials via this skill.
Review Dimensions
- Purpose & Capability
- okName/description match the SKILL.md content about Lisbon (history, urban resilience, tech scene). The skill declares no extra capabilities or resources, so nothing appears out of scope for an informational city guide.
- Instruction Scope
- okSKILL.md is static content with a summary and narrow 'read_when' triggers (research contexts). It does not instruct the agent to read files, access environment variables, call external endpoints, or collect unrelated data.
- Install Mechanism
- okNo install spec and no code files are present (instruction-only). Nothing is written to disk or downloaded during install.
- Credentials
- okThe skill requires no environment variables, credentials, or config paths. No sensitive access is requested.
- Persistence & Privilege
- okalways is false and the skill does not request elevated or persistent system privileges. Autonomous invocation is allowed (platform default) but the skill's scope is read-only informational.
