Back to skill
Skillv1.0.0

ClawScan security

Ritz Carlton · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 17, 2026, 2:13 AM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
An instruction-only informational skill about the Ritz‑Carlton brand that requests no credentials, installs nothing, and stays within its stated scope.
Guidance
This skill is an instruction-only content pack about Ritz‑Carlton and presents minimal risk because it requires no secrets, binaries, or installs. Before installing, consider whether you trust the publisher (source/homepage are unknown) and whether you need up-to-date or primary-source facts — for critical uses verify details against official Ritz‑Carlton / Marriott sources. Otherwise it is low-risk to enable.

Review Dimensions

Purpose & Capability
okName/description match the SKILL.md content (brand history, Gold Standards, flagship properties). The skill requests no binaries, env vars, or config paths—nothing disproportionate to an informational guide.
Instruction Scope
okSKILL.md contains only brand/background/service guidance and 'read_when' triggers. It does not instruct the agent to read local files, access environment variables, call external endpoints, or transmit data elsewhere.
Install Mechanism
okNo install spec and no code files are present (instruction-only). This is the lowest-risk installation model—nothing is written to disk or executed by the installer.
Credentials
okNo environment variables, credentials, or config paths are required. The declared permissions are proportionate to an informational skill.
Persistence & Privilege
okalways is false and model invocation is allowed by default. The skill does not request persistent privileges or modify other skills or system settings.