Back to skill
Skillv1.0.0

ClawScan security

Mccormick · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 29, 2026, 10:04 AM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
This is an instruction-only reference card about McCormick & Company; its declared purpose matches the content and it requests no credentials or installs.
Guidance
This skill is a safe, read-only reference card about McCormick. Before installing, note that the source is unknown and the content may be outdated or imprecise — if you need authoritative, up-to-date facts (financials, leadership, acquisitions), prefer official filings, the company website, or trusted news sources. If you want citations or automated data pulls (e.g., live financials), require a skill that declares appropriate APIs/credentials and an install mechanism.

Review Dimensions

Purpose & Capability
okName/description (company overview) match the SKILL.md content. The skill only provides factual/company reference material and does not declare unrelated requirements.
Instruction Scope
okSKILL.md is a static reference (company overview, timeline, facts) and a small read_when trigger list. It does not instruct the agent to access files, credentials, external endpoints, or perform actions outside providing informational content.
Install Mechanism
okNo install spec or code files are present; instruction-only skills pose minimal installation risk because nothing is written or executed on disk.
Credentials
okThe skill requests no environment variables, credentials, or config paths — appropriate for a read-only informational skill.
Persistence & Privilege
okalways is false, user-invocable is true, and autonomous invocation is allowed by default. The skill does not request persistent presence or modify other skills/configuration.