Back to skill
Skillv1.0.0

ClawScan security

Nytimes · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 27, 2026, 11:03 PM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
This is an instruction-only informational skill about The New York Times' digital-subscription strategy; it requires no credentials, installs, or special privileges and is internally consistent with its stated purpose.
Guidance
This skill is low-risk and appears coherent: it only provides background and analysis about The New York Times and does not request access to your system or secrets. Before installing, consider that (1) the source and homepage are unknown so verify the author's trustworthiness if that matters to you; (2) content may be stale or contain factual errors — cross-check important facts against primary sources; and (3) if you prefer tighter control, disable autonomous invocation for your agent or review what skills are allowed to run automatically.

Review Dimensions

Purpose & Capability
okThe name/description (analysis of NYT digital subscription and monetization) matches the SKILL.md content. The skill requests no binaries, env vars, or config paths — all proportional to an informational skill.
Instruction Scope
okSKILL.md contains only article-like content and a small 'read_when' guidance for when the agent should consult it. It does not instruct reading unrelated files, accessing credentials, or contacting external endpoints.
Install Mechanism
okNo install spec or code files are present (instruction-only). Nothing will be written to disk or downloaded by the skill itself.
Credentials
okThe skill declares no environment variables, credentials, or config paths — appropriate for a read-only knowledge snippet.
Persistence & Privilege
okalways is false and the skill does not request elevated or persistent privileges. Autonomous model invocation remains enabled by default (normal) but the skill itself has no special persistence demands.