Back to skill
Skillv1.0.0
ClawScan security
Mars Brand · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignApr 24, 2026, 4:03 PM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- This is an instruction-only informational skill about the Mars company with no installs, no required credentials, and no code — its requested capabilities match its description.
- Guidance
- From a security perspective this skill is low-risk: it is read-only content about the Mars company and asks for no credentials, binaries, or installs. Before installing, consider whether you need authoritative/updated company data (numbers and events in SKILL.md may be outdated or approximate). If you require primary-source or up-to-date financial information, prefer official company reports or reputable business databases.
Review Dimensions
- Purpose & Capability
- okThe skill is a pure informational/reference skill about Mars (history, brands, business) and declares no binaries, env vars, or config paths; those requirements align with an information-only purpose.
- Instruction Scope
- okSKILL.md contains only topical guidance (when to read, company timeline, analysis) and does not instruct the agent to read files, access system state, call external endpoints, or exfiltrate data. No broad or open-ended data collection is requested.
- Install Mechanism
- okNo install spec and no code files are present (instruction-only). Nothing will be written to disk or executed as part of installation.
- Credentials
- okThe skill requests no environment variables, credentials, or config paths — proportional for an informational skill.
- Persistence & Privilege
- okalways is false and autonomous invocation is allowed by default (normal). The skill does not request elevated or persistent system privileges.
