Back to skill
Skillv1.0.0

ClawScan security

Rimac Automobili · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 28, 2026, 11:05 PM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
This is an instruction-only content skill (an informational article about Rimac Automobili) with no code, no installs, and no requested credentials — its declared requirements align with its stated purpose.
Guidance
This skill appears low-risk because it is purely informational and requests no credentials, installs, or filesystem access. Before installing, consider whether you trust the unknown source/owner (no homepage or provenance is provided) and whether you need authoritative, up-to-date facts — the content may be correct but unverified. If you require verified data (e.g., for business decisions), cross-check with Rimac's official site or trusted publications. Otherwise, from a security standpoint it is coherent and proportionate.

Review Dimensions

Purpose & Capability
noteThe skill is an informational/content skill about Rimac Automobili and does not request binaries, environment variables, or config paths. That is consistent with a read-only knowledge/content skill. One provenance note: the skill lists no homepage or source and the registry owner ID is an opaque identifier, so the origin of the content is unknown (this is a content-quality/provenance issue, not a technical access risk).
Instruction Scope
okSKILL.md provides contextual guidance and factual narrative about Rimac; it does not instruct the agent to read local files, access environment variables, call external endpoints, or exfiltrate data. The documented 'read_when' contexts are reasonable and scoped to research/use of the content.
Install Mechanism
okNo install spec and no code files are present, so nothing will be downloaded or written to disk. This is the lowest-risk install posture.
Credentials
okThe skill requests no environment variables, credentials, or config paths, which is proportionate for an informational skill.
Persistence & Privilege
okDefaults are used (not always:true), and autonomous invocation is allowed (platform default). There is no evidence the skill will modify other skills or system settings.