Back to skill
Skillv1.0.1
ClawScan security
Whole Foods · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignApr 23, 2026, 9:27 AM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- This is an instruction-only informational skill about Whole Foods; its declared requirements and instructions are consistent with that purpose and it does not request credentials, install software, or perform out-of-scope actions.
- Guidance
- This skill is essentially a packaged article/analysis about Whole Foods and appears internally consistent. Before installing, consider provenance: the source and owner are unknown, so verify the content's accuracy and whether you trust this publisher. Because it has no code, it cannot exfiltrate secrets or execute actions, but content could be outdated or biased — treat factual claims (financial figures, timelines) as unverified and cross-check with authoritative sources if you rely on them.
Review Dimensions
- Purpose & Capability
- okThe name and description match the SKILL.md content: an encyclopedic/analysis entry about Whole Foods and Amazon integration. There are no environment variables, binaries, or installs requested that would be unrelated to an informational skill.
- Instruction Scope
- okSKILL.md contains historical, business-model, and analytical text intended for research/read_when triggers. It does not instruct the agent to read system files, access environment variables, call external endpoints, or transmit data beyond providing content for analyses.
- Install Mechanism
- okNo install spec or code files are present. As an instruction-only skill, it writes nothing to disk and has minimal attack surface from installation.
- Credentials
- okThe skill declares no required env vars, credentials, or config paths. There are no disproportionate or unexplained secret access requests.
- Persistence & Privilege
- okFlags show always:false and default invocation behavior. The skill does not request permanent presence or system-level changes and does not modify other skills' configs.
