Back to skill
Skillv1.0.0

ClawScan security

Cb Local Partnership Assessor · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 25, 2026, 5:14 AM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
The skill is a purely descriptive framework for assessing overseas partners and its declared inputs, outputs, and behavior match the files and runtime instructions provided.
Guidance
This skill appears internally consistent and purely descriptive, but it is not a substitute for legal, financial, or anti-corruption due diligence. Do not paste sensitive data (credentials, contracts with personal data, or proprietary documents) into prompts. Verify any partner claims independently (references, registries, public filings) before sharing confidential information or signing agreements, and obtain professional review for contracts or compliance-sensitive matters.

Review Dimensions

Purpose & Capability
okName, description, SKILL.md, README.md, ACCEPTANCE.md, and skill.json all describe the same descriptive assessment framework; no unrelated credentials, binaries, or services are requested.
Instruction Scope
okSKILL.md is instruction-only and explicitly states it does not execute code, call APIs, access the network, or perform external actions. The workflow and output modules are limited to generating frameworks, checklists, and playbooks.
Install Mechanism
okNo install spec and no code files — nothing is written to disk or downloaded. This is the lowest-risk installation posture for a skill.
Credentials
okNo required environment variables, credentials, or config paths are declared or referenced; the skill's stated needs are proportional to its descriptive purpose.
Persistence & Privilege
okSkill is user-invocable, not always-on. Autonomous model invocation is allowed (platform default) but the skill has no capabilities that would leverage that to perform external actions.