Back to skill
Skillv1.0.0

ClawScan security

Petrochina · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 16, 2026, 10:57 PM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
This instruction-only skill is internally consistent with its stated purpose (providing PetroChina background and market overview) and requests no sensitive access or installs.
Guidance
This skill appears safe and coherent: it only provides structured information about PetroChina and asks for no credentials or installs. Before relying on its outputs, verify factual claims against official sources (company website, filings, reputable news) because the model can be outdated or hallucinate details. If the skill is later updated to include an install spec or environment variables, reassess permissions and any downloaded code before installing.

Review Dimensions

Purpose & Capability
okSkill name, description, and SKILL.md content all align: the skill is a simple informational/canned-response helper about PetroChina and does not declare unrelated requirements.
Instruction Scope
okSKILL.md contains only content templates and trigger phrases; it does not instruct reading files, accessing environment variables, contacting unexpected endpoints, or collecting unrelated data.
Install Mechanism
okNo install spec and no code files — nothing is downloaded or written to disk by the skill itself.
Credentials
okThe skill declares no environment variables, credentials, or config paths; requested access is proportionate to an informational skill.
Persistence & Privilege
okalways is false (default). The skill can be invoked by the agent (normal behavior) but does not request elevated persistence or cross-skill configuration changes.