Back to skill
Skillv1.0.0

ClawScan security

Superbowl · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 17, 2026, 8:56 AM
Verdict
Benign
Confidence
high
Model
gpt-5-mini
Summary
This is an instruction-only Super Bowl information skill whose declared requirements, instructions, and privileges are consistent with its stated purpose and it requests no extra permissions or installs.
Guidance
This skill appears coherent and low-risk because it is instruction-only and asks for no credentials or installs. Consider that the SKILL.md content is static and the source/homepage is unknown, so factual details (scores, recent champions, ad prices) may be outdated or unsourced. If you need live schedules or up-to-date results, prefer skills that declare a reliable data source or API key (and review those permissions). Otherwise it is reasonable to use this for general Super Bowl background and historical summaries.

Review Dimensions

Purpose & Capability
okName and description (Super Bowl rules, history, players, schedule/results) match the SKILL.md content. The skill declares no binaries, env vars, or config paths — which is proportional for a read-only informational skill.
Instruction Scope
okSKILL.md contains static informational content and simple 'read_when' triggers. It does not instruct the agent to read files, access unrelated environment variables, call external endpoints, or transmit data elsewhere.
Install Mechanism
okNo install spec and no code files are present (instruction-only). This is the lowest-risk model and there is nothing written to disk or executed at install time.
Credentials
okThe skill requests no credentials, env vars, or config paths. There are no disproportionate or unrelated permissions requested.
Persistence & Privilege
okThe skill is not marked always:true and uses default autonomous invocation. It does not request persistent system presence or modify other skills' configuration.