Back to skill
Skillv1.0.0

ClawScan security

Tag Heuer · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 17, 2026, 8:57 AM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
This is an instruction-only skill that provides a Tag Heuer brand guide; it requests no credentials, performs no installs, and its runtime instructions stay within the described purpose.
Guidance
This skill appears low-risk: it only supplies brand background and asks for nothing else. Before installing, consider that the source and homepage are not provided (provenance is unknown) — if you need authoritative or up-to-date facts (dates, revenue, partnership status) verify against official TAG Heuer or LVMH sources. Because it is instruction-only and requests no credentials, there is minimal privacy/security exposure. If you have stricter policies, prefer skills with a verifiable homepage or known publisher.

Review Dimensions

Purpose & Capability
okName/description (Tag Heuer brand guide) matches the SKILL.md content. The skill requires no binaries, env vars, or config paths — consistent with an information/reference skill.
Instruction Scope
okSKILL.md contains only brand information and a 'read_when' trigger list for when to present that information. It does not instruct the agent to read local files, environment variables, or contact external endpoints beyond serving brand content.
Install Mechanism
okNo install spec or code files are present (instruction-only), so there is nothing written to disk or downloaded during installation.
Credentials
okNo environment variables, credentials, or config paths are requested. The skill does not ask for any secrets or unrelated access.
Persistence & Privilege
okalways is false (default) and model invocation is allowed (default). Those defaults are normal for a user-invocable informational skill and are not combined with any broad privileges or credential access.