Back to skill
Skillv1.0.0

ClawScan security

Porsche Automotive · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 26, 2026, 4:08 PM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
This is an instruction-only research/analysis skill about Porsche whose declared requirements and runtime instructions match its stated purpose and do not request extra privileges or installs.
Guidance
This skill appears internally consistent and low-risk: it only contains research prompts and no installs, secrets, or system access. However, the source is unknown — if provenance matters to you, prefer skills from trusted publishers. Also remember that "benign" means coherent, not necessarily accurate: review outputs for factual correctness and avoid giving the agent access to sensitive documents you don't want included in the analysis.

Review Dimensions

Purpose & Capability
okName and description claim analytical research about Porsche; the SKILL.md contains topic prompts and background text consistent with that purpose and does not ask for unrelated capabilities (cloud keys, system access, or extra tooling).
Instruction Scope
okThe SKILL.md provides research/read_when prompts and prose for analysis. It does not instruct the agent to read local files, environment variables, system paths, or to transmit data to external endpoints beyond performing analysis, so scope is limited to the stated research task.
Install Mechanism
okNo install spec and no code files are present (instruction-only). Nothing will be written to disk or downloaded during install.
Credentials
okThe skill declares no required environment variables, credentials, or config paths — proportional to an analysis-only skill.
Persistence & Privilege
okalways is false and there are no signs the skill tries to alter agent-wide settings or persist credentials. Autonomous invocation is allowed (platform default) but is not combined with elevated privileges here.