Back to skill
Skillv1.0.0

ClawScan security

Tesla Inc · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 29, 2026, 4:10 PM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
This is an instruction-only informational skill about Tesla that asks for no credentials, installs nothing, and its runtime instructions are limited to serving factual content — the pieces are internally consistent.
Guidance
This skill appears to be a read-only, informational text bundle about Tesla and does not request access to your system or secrets. Before installing: confirm you trust the publisher (source/homepage are unknown), because the content may be outdated or contain inaccuracies; if you need authoritative or up-to-date figures (financials, deliveries, prices), verify them against official filings or Tesla's website. Autonomous invocation is allowed by default on the platform — that is normal for skills and not a red flag here, but you can disable the skill for autonomous use if you prefer manual invocation only.

Review Dimensions

Purpose & Capability
okName/description promise (history, products, business model, tech) matches the SKILL.md content. The skill requests no binaries, env vars, or config paths that would be unrelated to an informational summary.
Instruction Scope
okSKILL.md contains only static content and read_when triggers for relevant topics; it does not instruct the agent to run commands, read local files, access unrelated environment variables, or send data to external endpoints.
Install Mechanism
okNo install spec and no code files (instruction-only). Nothing is written to disk or downloaded as part of installation.
Credentials
okNo environment variables, credentials, or config paths are requested. The skill does not ask for secrets or unrelated service tokens.
Persistence & Privilege
okalways is false and default autonomous invocation is allowed (platform default). The skill does not request permanent presence or system-level config changes.