Back to skill
Skillv1.0.0

ClawScan security

Moutai · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 29, 2026, 3:06 PM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
This is an instruction-only informational skill about Kweichow Moutai with no code, no installs, and no credential or system access — its declared behavior matches what it requests.
Guidance
This skill appears low-risk: it only contains a static analysis document and does not request credentials, system access, or install code. Before installing, consider that the content has no cited sources and the owner is unknown — verify any facts or financial figures against reputable sources if you will rely on them for decisions. If you expect dynamic functionality (live data, API queries, or sourcing), confirm the skill actually implements those and whether it will need credentials or network access.

Review Dimensions

Purpose & Capability
okName/description promise (analysis of Kweichow Moutai) matches the SKILL.md content. The skill requests no binaries, env vars, or config paths that would be unrelated to an informational analysis.
Instruction Scope
okSKILL.md is a static, self-contained report (history, business model, metrics) and does not instruct the agent to read local files, access environment variables, call external endpoints, or exfiltrate data.
Install Mechanism
okNo install specification is present; this is instruction-only so nothing will be written to disk or downloaded during install.
Credentials
okNo environment variables, credentials, or config paths are required; requested privileges are minimal and proportionate to an informational skill.
Persistence & Privilege
okalways is false and the skill does not request persistent system presence or modify other skills/configuration. Autonomous invocation is allowed by default but is not combined with other concerning privileges.