Back to skill
Skillv1.0.0

ClawScan security

Tropicana · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 29, 2026, 12:02 PM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
This is an instruction-only informational skill about the Tropicana brand; it requests no credentials, no installs, and its runtime instructions are limited to providing brand content, so its declared purpose matches its behavior.
Guidance
This skill appears coherent and low-risk: it only provides static brand information and asks for nothing from your environment. Consider that the source is unknown — verify any facts the skill provides against trusted references before using them for decisions, and be aware that informational content may be out of date or imprecise.

Review Dimensions

Purpose & Capability
okName and description claim a brand overview; SKILL.md contains only brand history, business analysis, facts and 'read_when' triggers for relevant conversations. There are no unrelated requirements (no env vars, binaries, or config paths).
Instruction Scope
okSKILL.md is a content document (brand overview and guidance for when to read it). It does not instruct the agent to read files, access environment variables, call external endpoints, or collect/transmit user data beyond producing informational output.
Install Mechanism
okNo install spec and no code files — nothing will be written to disk or installed. This is the lowest-risk pattern and is proportionate for an informational skill.
Credentials
okThe skill declares no required environment variables, credentials, or config paths. There are no unexpected secrets or credential requests.
Persistence & Privilege
okalways is false and model invocation is allowed (default). The skill does not request persistent system privileges or modify other skills or system settings.