Back to skill
Skillv1.0.0
ClawScan security
Lufthansa Group · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignApr 29, 2026, 10:07 PM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- This is an instruction-only, informational skill about the Lufthansa Group; it requests no credentials, installs nothing, and its runtime instructions are limited to providing/backgrounding airline information — nothing appears out of scope.
- Guidance
- This skill is low-risk: it only contains static background material about Lufthansa Group and asks for nothing. Consider: (1) provenance — the skill's source/homepage is unknown, so verify any important facts (financials, counts, dates) against official or up-to-date sources before relying on them; (2) if you combine this skill with other skills that do network access or request credentials, review those other skills carefully (this skill itself does not request secrets); (3) if you need authoritative or current data (schedules, financial filings), prefer official APIs or the airline's website.
Review Dimensions
- Purpose & Capability
- okThe skill's name and description match the SKILL.md content (background, strategy, and facts about Lufthansa Group). There are no unrelated required binaries, environment variables, or config paths. The only minor note: the skill's declared source/homepage is unknown, but that affects provenance, not capability alignment.
- Instruction Scope
- okSKILL.md contains static informational text and a small 'read_when' list telling the agent when to surface this content. It does not instruct the agent to read local files, access environment variables, call external endpoints, or transmit data elsewhere. No scope creep detected.
- Install Mechanism
- okNo install spec and no code files are present (instruction-only). Nothing will be written to disk or downloaded during install.
- Credentials
- okThe skill requests no environment variables or credentials and does not ask for access to system configuration or secrets — its requests are minimal and proportionate to an informational skill.
- Persistence & Privilege
- okalways is false and the skill is user-invocable. disable-model-invocation is false (normal), meaning the agent could autonomously call the skill if permitted by policy; this is standard and not excessive for this content-only skill.
