Back to skill
Skillv1.0.0

ClawScan security

Legal Discovery Request Planner · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 26, 2026, 1:09 PM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
This is a document-only, descriptive skill whose requested resources and runtime instructions match its stated purpose and contain no code, credentials, or install steps.
Guidance
This skill appears coherent and low-risk because it is documentation-only and declares no network or code execution. Before installing: (1) remember it is informational only — verify outputs with qualified counsel and local rules; (2) avoid pasting confidential or privileged client data into the chat (the skill does not request credentials but any user-provided case facts could be sensitive); and (3) if you later modify this package to add handlers or scripts, re-evaluate for network calls, credentials, or unexpected install behavior.

Review Dimensions

Purpose & Capability
okName, description, and files are all descriptive-only and focused on legal discovery planning. There are no declared env vars, binaries, or install steps that would be unrelated to the stated purpose.
Instruction Scope
okSKILL.md contains only guidance, templates, checklists, inputs to collect, and explicit legal/ethical limitations. It does not instruct the agent to read files, call external APIs, execute commands, or access system configuration.
Install Mechanism
okNo install spec and no code files — the package is instruction-only. ACCEPTANCE.md enforces that no handler/scripts/executables are present, so there is nothing written to disk or fetched at install time.
Credentials
okNo environment variables, credentials, or config paths are requested. The skill does not need any external secrets or cloud access to perform its described functions.
Persistence & Privilege
okalways is false and there is no install or runtime component that would request persistent privileges or modify other skills or system-wide settings.