Back to skill
Skillv1.0.0

ClawScan security

Riyadh · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 26, 2026, 7:06 PM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
This is an instruction-only, informational skill about Riyadh whose content and requirements match its stated purpose and do not request credentials, installs, or access to system resources.
Guidance
This skill is informational and low-risk: it doesn't request credentials or install anything. Before using its content for decisions (investing, policy, planning), verify facts against primary sources because the SKILL.md is a static summary that may be outdated or simplified. If you plan to allow autonomous agent use, remember the agent could cite or act on this content — ensure you trust its outputs and supplement with real-time data where accuracy matters.

Review Dimensions

Purpose & Capability
okName, description, and SKILL.md are all about Riyadh's history, economy, and development; the skill declares no credentials, binaries, or unrelated capabilities.
Instruction Scope
okSKILL.md contains static informational content and a small 'read_when' list (contexts for use). It does not instruct the agent to read files, access environment variables, call external endpoints, or exfiltrate data.
Install Mechanism
okNo install spec and no code files — nothing is written to disk or executed at install time.
Credentials
okThe skill requires no environment variables, credentials, or config paths; requested access is proportionate to an informational skill.
Persistence & Privilege
okalways is false and model invocation is enabled (the platform default). There is no indication the skill requests elevated persistence or modifies other skills/config.