Back to skill
Skillv1.0.0

ClawScan security

Square Enix · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 17, 2026, 7:48 AM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
This is a read-only informational skill (knowledge card) about Square Enix that requests no credentials, performs no installs, and its runtime instructions stay within the stated purpose.
Guidance
This skill is essentially a static knowledge card and appears safe to install from a security perspective because it requests no credentials and has no install steps. Before relying on its content, manually verify any factual claims (dates, company events, named individuals) because the SKILL.md contains some unusual or likely inaccurate details. If you need authoritative information (for publication, business use, or legal matters), cross-check against official sources (Square Enix corporate site, reputable game history references).

Review Dimensions

Purpose & Capability
okThe skill's name and description match the SKILL.md content: it's a static knowledge card about Square Enix. It declares no binaries, no env vars, and no installs — which is appropriate for an informational skill.
Instruction Scope
noteThe instructions are limited to presenting company history and recommended reading triggers (read_when). They do not request access to files, credentials, or external endpoints. Note: the SKILL.md contains factual assertions (some unusual/incorrect phrasing, e.g., uncommon names/claims about founders/CEO) — this is a content accuracy issue, not a security one; verify facts before using them as authoritative.
Install Mechanism
okNo install spec and no code files are present (instruction-only). That minimizes disk/network risk; nothing will be downloaded or executed by the install step.
Credentials
okThe skill requires no environment variables, no credentials, and no config paths. The requested access is proportional (none) for an informational card.
Persistence & Privilege
okDefault runtime flags are used (always: false, model invocation allowed). The skill does not request permanent presence or elevated privileges and does not modify other skills or system settings.