Back to skill
Skillv1.0.0
ClawScan security
Rimac Automobili · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignApr 28, 2026, 11:05 PM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- This is an instruction-only content skill (an informational article about Rimac Automobili) with no code, no installs, and no requested credentials — its declared requirements align with its stated purpose.
- Guidance
- This skill appears low-risk because it is purely informational and requests no credentials, installs, or filesystem access. Before installing, consider whether you trust the unknown source/owner (no homepage or provenance is provided) and whether you need authoritative, up-to-date facts — the content may be correct but unverified. If you require verified data (e.g., for business decisions), cross-check with Rimac's official site or trusted publications. Otherwise, from a security standpoint it is coherent and proportionate.
Review Dimensions
- Purpose & Capability
- noteThe skill is an informational/content skill about Rimac Automobili and does not request binaries, environment variables, or config paths. That is consistent with a read-only knowledge/content skill. One provenance note: the skill lists no homepage or source and the registry owner ID is an opaque identifier, so the origin of the content is unknown (this is a content-quality/provenance issue, not a technical access risk).
- Instruction Scope
- okSKILL.md provides contextual guidance and factual narrative about Rimac; it does not instruct the agent to read local files, access environment variables, call external endpoints, or exfiltrate data. The documented 'read_when' contexts are reasonable and scoped to research/use of the content.
- Install Mechanism
- okNo install spec and no code files are present, so nothing will be downloaded or written to disk. This is the lowest-risk install posture.
- Credentials
- okThe skill requests no environment variables, credentials, or config paths, which is proportionate for an informational skill.
- Persistence & Privilege
- okDefaults are used (not always:true), and autonomous invocation is allowed (platform default). There is no evidence the skill will modify other skills or system settings.
