Back to skill
Skillv1.0.0
ClawScan security
Superbowl · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignApr 17, 2026, 8:56 AM
- Verdict
- Benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- This is an instruction-only Super Bowl information skill whose declared requirements, instructions, and privileges are consistent with its stated purpose and it requests no extra permissions or installs.
- Guidance
- This skill appears coherent and low-risk because it is instruction-only and asks for no credentials or installs. Consider that the SKILL.md content is static and the source/homepage is unknown, so factual details (scores, recent champions, ad prices) may be outdated or unsourced. If you need live schedules or up-to-date results, prefer skills that declare a reliable data source or API key (and review those permissions). Otherwise it is reasonable to use this for general Super Bowl background and historical summaries.
Review Dimensions
- Purpose & Capability
- okName and description (Super Bowl rules, history, players, schedule/results) match the SKILL.md content. The skill declares no binaries, env vars, or config paths — which is proportional for a read-only informational skill.
- Instruction Scope
- okSKILL.md contains static informational content and simple 'read_when' triggers. It does not instruct the agent to read files, access unrelated environment variables, call external endpoints, or transmit data elsewhere.
- Install Mechanism
- okNo install spec and no code files are present (instruction-only). This is the lowest-risk model and there is nothing written to disk or executed at install time.
- Credentials
- okThe skill requests no credentials, env vars, or config paths. There are no disproportionate or unrelated permissions requested.
- Persistence & Privilege
- okThe skill is not marked always:true and uses default autonomous invocation. It does not request persistent system presence or modify other skills' configuration.
