Back to skill
Skillv1.0.0

ClawScan security

Philadelphia PA · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 29, 2026, 3:10 PM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
The skill is internally consistent: it provides descriptive content about Philadelphia and requires no binaries, credentials, installs, or special privileges.
Guidance
This skill appears safe from a permissions and install perspective: it only contains prewritten content about Philadelphia and asks for no credentials or system access. Before relying on factual claims (population, visitor counts, rankings), verify sources and dates — the SKILL.md includes specific statistics and historical assertions that may be outdated or imprecise. If you need citations or official data, ask the skill author to include sources or link to authoritative references.

Review Dimensions

Purpose & Capability
okThe name, description, and SKILL.md all describe the same purpose (history, institutions, and economic profile of Philadelphia). There are no unrelated requirements (no env vars, binaries, or config paths).
Instruction Scope
okSKILL.md contains only topical content and trigger conditions for when to present that content. It does not instruct the agent to read files, access environment variables, run commands, or transmit data to external endpoints.
Install Mechanism
okNo install spec and no code files — this is an instruction-only skill. Nothing is written to disk or downloaded during install.
Credentials
okThe skill requests no environment variables, credentials, or config paths; this is proportionate to a read-only informational skill.
Persistence & Privilege
okalways is false and the skill does not request elevated persistence or modify other skills. Model invocation is allowed (platform default) which is appropriate for this type of skill.