Back to skill
Skillv1.0.0
ClawScan security
Moutai · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignApr 29, 2026, 3:06 PM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- This is an instruction-only informational skill about Kweichow Moutai with no code, no installs, and no credential or system access — its declared behavior matches what it requests.
- Guidance
- This skill appears low-risk: it only contains a static analysis document and does not request credentials, system access, or install code. Before installing, consider that the content has no cited sources and the owner is unknown — verify any facts or financial figures against reputable sources if you will rely on them for decisions. If you expect dynamic functionality (live data, API queries, or sourcing), confirm the skill actually implements those and whether it will need credentials or network access.
Review Dimensions
- Purpose & Capability
- okName/description promise (analysis of Kweichow Moutai) matches the SKILL.md content. The skill requests no binaries, env vars, or config paths that would be unrelated to an informational analysis.
- Instruction Scope
- okSKILL.md is a static, self-contained report (history, business model, metrics) and does not instruct the agent to read local files, access environment variables, call external endpoints, or exfiltrate data.
- Install Mechanism
- okNo install specification is present; this is instruction-only so nothing will be written to disk or downloaded during install.
- Credentials
- okNo environment variables, credentials, or config paths are required; requested privileges are minimal and proportionate to an informational skill.
- Persistence & Privilege
- okalways is false and the skill does not request persistent system presence or modify other skills/configuration. Autonomous invocation is allowed by default but is not combined with other concerning privileges.
