Back to skill
Skillv1.0.0

ClawScan security

Manila · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 29, 2026, 10:04 AM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
This is an instruction-only informational card about Manila; it asks for no credentials, installs nothing, and its content and requirements are internally consistent.
Guidance
This skill appears low-risk: it’s just a static reference card about Manila with no installs or credential requests. Before installing, verify you trust the publisher (source unknown) and review the SKILL.md yourself. Be cautious if a future version adds an install step, required env vars, or an 'always: true' flag — those would raise new security considerations. Also remember content accuracy is not guaranteed; treat the data as informational rather than authoritative.

Review Dimensions

Purpose & Capability
okThe skill's name and description are a simple city overview; the SKILL.md provides that content and no extras. There are no unrelated required binaries, env vars, or configs.
Instruction Scope
okSKILL.md contains static informational text and trigger metadata (read_when). It does not instruct the agent to read files, call external endpoints, access credentials, or run commands.
Install Mechanism
okNo install spec and no code files — nothing is downloaded or written to disk. Instruction-only skills have minimal install risk.
Credentials
okThe skill declares no required environment variables, credentials, or config paths; nothing requesting secrets is present.
Persistence & Privilege
okalways is false and there is no indication the skill modifies agent/system configuration or demands persistent presence or elevated privileges.