Back to skill
Skillv1.0.0
ClawScan security
Ritz Carlton · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignApr 17, 2026, 2:13 AM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- An instruction-only informational skill about the Ritz‑Carlton brand that requests no credentials, installs nothing, and stays within its stated scope.
- Guidance
- This skill is an instruction-only content pack about Ritz‑Carlton and presents minimal risk because it requires no secrets, binaries, or installs. Before installing, consider whether you trust the publisher (source/homepage are unknown) and whether you need up-to-date or primary-source facts — for critical uses verify details against official Ritz‑Carlton / Marriott sources. Otherwise it is low-risk to enable.
Review Dimensions
- Purpose & Capability
- okName/description match the SKILL.md content (brand history, Gold Standards, flagship properties). The skill requests no binaries, env vars, or config paths—nothing disproportionate to an informational guide.
- Instruction Scope
- okSKILL.md contains only brand/background/service guidance and 'read_when' triggers. It does not instruct the agent to read local files, access environment variables, call external endpoints, or transmit data elsewhere.
- Install Mechanism
- okNo install spec and no code files are present (instruction-only). This is the lowest-risk installation model—nothing is written to disk or executed by the installer.
- Credentials
- okNo environment variables, credentials, or config paths are required. The declared permissions are proportionate to an informational skill.
- Persistence & Privilege
- okalways is false and model invocation is allowed by default. The skill does not request persistent privileges or modify other skills or system settings.
