Back to skill
Skillv1.0.0
ClawScan security
Manila · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignApr 29, 2026, 10:04 AM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- This is an instruction-only informational card about Manila; it asks for no credentials, installs nothing, and its content and requirements are internally consistent.
- Guidance
- This skill appears low-risk: it’s just a static reference card about Manila with no installs or credential requests. Before installing, verify you trust the publisher (source unknown) and review the SKILL.md yourself. Be cautious if a future version adds an install step, required env vars, or an 'always: true' flag — those would raise new security considerations. Also remember content accuracy is not guaranteed; treat the data as informational rather than authoritative.
Review Dimensions
- Purpose & Capability
- okThe skill's name and description are a simple city overview; the SKILL.md provides that content and no extras. There are no unrelated required binaries, env vars, or configs.
- Instruction Scope
- okSKILL.md contains static informational text and trigger metadata (read_when). It does not instruct the agent to read files, call external endpoints, access credentials, or run commands.
- Install Mechanism
- okNo install spec and no code files — nothing is downloaded or written to disk. Instruction-only skills have minimal install risk.
- Credentials
- okThe skill declares no required environment variables, credentials, or config paths; nothing requesting secrets is present.
- Persistence & Privilege
- okalways is false and there is no indication the skill modifies agent/system configuration or demands persistent presence or elevated privileges.
