Back to skill
Skillv1.0.0
ClawScan security
Toys R Us · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignApr 29, 2026, 12:05 AM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- This is an instruction-only, read-only informational skill about the history and business of Toys "R" Us; it has no code, no installs, and requests no credentials or system access, so its declared behavior is coherent with its requirements.
- Guidance
- This skill appears to be a harmless, read-only informational brief. Before installing, consider whether you need a dedicated skill for this static content (you could instead paste or store the text elsewhere), verify the publisher if provenance matters (owner ID is unknown), and be aware that "benign" only means internally consistent — always avoid granting credentials or extra privileges to skills unless they explicitly need them.
Review Dimensions
- Purpose & Capability
- okThe name/description promise a historical/business briefing about Toys "R" Us; the SKILL.md contains exactly that material and does not declare or require unrelated capabilities, binaries, or credentials.
- Instruction Scope
- okSKILL.md is a static informational document with a short 'read_when' context list. It does not instruct the agent to read local files, access environment variables, call external endpoints, or transmit data outside normal agent responses.
- Install Mechanism
- okNo install spec and no code files are present; nothing is downloaded or written to disk by the skill itself, which is the lowest-risk installation model.
- Credentials
- okThe skill requires no environment variables, credentials, or config paths. There is no disproportionate access requested relative to the stated informational purpose.
- Persistence & Privilege
- okFlags are default (not always:true). The skill can be invoked by the agent (normal), but it does not request persistent privileges or modify other skills or system configuration.
