Back to skill
Skillv1.0.0
ClawScan security
Pdd Holdings · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignApr 22, 2026, 7:23 AM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- This is a simple, instruction-only informational skill that provides a company profile of PDD Holdings and does not request credentials, install software, or instruct the agent to access unrelated system resources.
- Guidance
- This skill appears to be an informational company profile and is internally consistent. If you install it, note it can be invoked by the agent (normal behavior) but it does not request credentials or install code. As with any informational source, verify factual claims (revenues, user counts, dates) against authoritative sources before making financial or operational decisions.
Review Dimensions
- Purpose & Capability
- okThe skill's name and description match the provided content: a company profile of PDD Holdings/拼多多/Temu. It requires no binaries, credentials, or config paths—consistent with an informational skill.
- Instruction Scope
- okSKILL.md contains static company information and a short 'read_when' trigger list. It does not instruct the agent to read local files, access environment variables, call external endpoints, or exfiltrate data.
- Install Mechanism
- okNo install spec and no code files are present (instruction-only). Nothing is written to disk or fetched at install time.
- Credentials
- okThe skill requests no environment variables or credentials (primaryEnv none). There are no disproportionate credential requests.
- Persistence & Privilege
- ok(always) is false; the skill is user-invocable and allows model invocation (platform default). There is no indication it modifies other skills or requires permanent elevated presence.
