Back to skill
Skillv1.0.0

ClawScan security

Nordstrom · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 16, 2026, 1:13 PM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
This is a read-only brand guide about Nordstrom with no installs, no required credentials, and instructions that match its stated purpose.
Guidance
This skill is an instruction-only informational guide about the Nordstrom brand and appears internally consistent and low-risk: it asks for no credentials and performs no installs. Consider that the source is unknown — verify factual claims before relying on them for decisions (dates, financial figures, store counts can become outdated). If you plan to let an autonomous agent use this skill, remember it can be invoked to generate responses, but it cannot access your files or credentials through this skill.

Review Dimensions

Purpose & Capability
okName/description (Nordstrom brand guide) align with the SKILL.md content. The skill requests no binaries, env vars, or config paths — all proportional to a documentation-only skill.
Instruction Scope
okSKILL.md is static brand/history/operations content and contains no runtime commands, file reads, or instructions to access external endpoints or secrets. It confines itself to the stated purpose.
Install Mechanism
okNo install specification or code files are present (instruction-only), so nothing is written to disk or fetched at install time.
Credentials
okNo environment variables, credentials, or config paths are requested. There is no disproportionate access requested for the skill's claimed function.
Persistence & Privilege
okalways is false and model invocation is allowed (the platform default). The skill does not request elevated or permanent presence or modify other skills or system settings.