Back to skill
Skillv1.0.0

ClawScan security

Nashville · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 24, 2026, 4:07 PM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
This is a self-contained, instruction-only informational skill about Nashville with no external installs, credentials, or system access — its behavior matches its description.
Guidance
This skill is coherent and low-risk: it only supplies static information about Nashville and does not request access to your system or secrets. Before relying on specific claims (population numbers, industry rankings, references to Tesla or relative medical-industry size), verify time-sensitive facts against authoritative sources because the markdown is static and may become outdated or contain imprecise comparative statements. Also note there is no homepage or source metadata listed — if provenance matters, ask the author for citations or prefer skills that cite primary data sources.

Review Dimensions

Purpose & Capability
okThe skill's name and description (city overview of Nashville) align with the SKILL.md content. It does not request unrelated capabilities, binaries, or credentials.
Instruction Scope
okSKILL.md contains static, topical content and read_when hints for when the agent should use it. It does not instruct the agent to read files, access environment variables, call external endpoints, or transmit data outside the agent context.
Install Mechanism
okNo install specification or code is present (instruction-only). This is lowest-risk because nothing is downloaded or written to disk.
Credentials
okThe skill declares no required environment variables, credentials, or config paths. There is no disproportionate credential request.
Persistence & Privilege
okFlags are default (always:false, user-invocable:true). The skill does not request permanent presence or elevated privileges and does not modify system or other skills' configs.