Back to skill
Skillv1.0.0
ClawScan security
Osaka City · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignApr 28, 2026, 11:05 PM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- This is an instruction-only, informational skill about Osaka whose requested resources and runtime instructions match its description and raise no evident security concerns.
- Guidance
- This skill appears to be a straightforward informational guide about Osaka and is internally consistent. Because the registry source is listed as "unknown," you may want to: (1) preview the full SKILL.md (the listing appears truncated) to confirm there are no hidden instructions; (2) prefer skills from known authors or registries if provenance matters; and (3) avoid granting any credentials or extra permissions—none are required here. Overall risk is low, but always review the full text before enabling autonomous invocation if you have privacy or compliance concerns.
Review Dimensions
- Purpose & Capability
- okName, description, and SKILL.md content all describe Osaka's history, economy, and food culture; there are no unrelated requirements (no env vars, binaries, or config paths) that would be disproportionate to that purpose.
- Instruction Scope
- okSKILL.md is purely descriptive and scoped to reading/producing informational content (research contexts listed). It does not instruct the agent to read local files, access credentials, call external endpoints, or exfiltrate data.
- Install Mechanism
- okThere is no install spec and no code files—this is the lowest-risk model (nothing is written to disk or fetched at install time).
- Credentials
- okThe skill declares no environment variables, credentials, or config paths. No sensitive access is requested or implied by the instructions.
- Persistence & Privilege
- okFlags are default (always:false, user-invocable:true). The skill does not request persistent or elevated privileges and does not modify agent or system configuration.
