Back to skill
Skillv1.0.0

ClawScan security

Mars · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 16, 2026, 8:01 AM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
This is an instruction-only informational skill about Mars, Incorporated: it contains no code, does not request credentials or install software, and is internally consistent with its stated purpose.
Guidance
This skill appears safe from a technical/permission perspective: it is read-only informational content that neither installs code nor requests secrets. The main remaining risk is provenance and accuracy — the source is unknown and there is no homepage or publisher info. Before relying on facts (financial figures, executive names, market positions), verify key claims against reputable sources (company filings, major business press, official Mars communications). If you require provenance or auditability, prefer skills with a verifiable homepage or known publisher.

Review Dimensions

Purpose & Capability
okName and description match the SKILL.md content (company history, brands, market data). The skill does not request unrelated permissions or binaries.
Instruction Scope
okSKILL.md is purely descriptive content and a small set of 'read_when' triggers; it does not instruct the agent to read local files, call external endpoints, or access environment variables beyond none declared.
Install Mechanism
okNo install spec and no code files — nothing will be written to disk or downloaded during install.
Credentials
okThe skill requires no environment variables, credentials, or config paths; requested access is minimal and proportionate to an informational skill.
Persistence & Privilege
okalways is false and it does not request persistent or cross-skill configuration. Autonomous invocation is allowed (platform default) but is not combined with any broad privileges.