Back to skill
Skillv1.0.0
ClawScan security
Petrochina · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignApr 16, 2026, 10:57 PM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- This instruction-only skill is internally consistent with its stated purpose (providing PetroChina background and market overview) and requests no sensitive access or installs.
- Guidance
- This skill appears safe and coherent: it only provides structured information about PetroChina and asks for no credentials or installs. Before relying on its outputs, verify factual claims against official sources (company website, filings, reputable news) because the model can be outdated or hallucinate details. If the skill is later updated to include an install spec or environment variables, reassess permissions and any downloaded code before installing.
Review Dimensions
- Purpose & Capability
- okSkill name, description, and SKILL.md content all align: the skill is a simple informational/canned-response helper about PetroChina and does not declare unrelated requirements.
- Instruction Scope
- okSKILL.md contains only content templates and trigger phrases; it does not instruct reading files, accessing environment variables, contacting unexpected endpoints, or collecting unrelated data.
- Install Mechanism
- okNo install spec and no code files — nothing is downloaded or written to disk by the skill itself.
- Credentials
- okThe skill declares no environment variables, credentials, or config paths; requested access is proportionate to an informational skill.
- Persistence & Privilege
- okalways is false (default). The skill can be invoked by the agent (normal behavior) but does not request elevated persistence or cross-skill configuration changes.
