Back to skill
Skillv1.0.0
ClawScan security
Macy · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignApr 24, 2026, 10:05 AM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- This is an instruction-only informational skill about Macy's with static content and no installs, required credentials, or elevated privileges — its requirements align with its stated purpose.
- Guidance
- This skill appears internally consistent and low risk: it only provides static background on Macy's and requests no credentials or installs. The source is 'unknown' — if you need authoritative or up-to-date research, cross-check facts against reputable sources (official Macy's releases, financial reports, or trusted news). Because it's user-invocable and can be called by the agent, consider whether you want autonomous agent access to any skills in your environment, but this particular skill does not ask for sensitive data or elevated privileges.
Review Dimensions
- Purpose & Capability
- okName and description claim an informational retail/history skill about Macy's; the SKILL.md contains historical timeline, business model, metrics and trivia that match that purpose. There are no unrelated capabilities requested.
- Instruction Scope
- okSKILL.md is static content and a short 'read_when' trigger list; it does not instruct the agent to run shell commands, access files, query external endpoints, or read environment variables beyond none declared. Scope is limited to providing background and analysis on Macy's.
- Install Mechanism
- okNo install specification and no code files — nothing will be downloaded or written to disk by an installer. This is the lowest-risk install model.
- Credentials
- okThe skill declares no required environment variables, credentials, or config paths. There are no excessive or unrelated secrets requested.
- Persistence & Privilege
- okalways is false (not forced into every agent run). disable-model-invocation is false (agent may invoke it autonomously), which is the platform default and acceptable here given the skill's limited scope.
