Medication Refill Bottle Flag Card

PassAudited by ClawScan on May 11, 2026.

Overview

The visible artifacts describe a no-code printable refill organization aid with clear medical and privacy limits, though the registry capability signals should be checked because they mention wallet, purchase, and credential capabilities that the files themselves do not use.

This appears safe to use as a printable organization template if you keep it to non-clinical refill tracking. Do not enter passwords, portal codes, full insurance or payment numbers, or medical record identifiers. If the platform asks for wallet, purchase, credential, or account permissions, decline them because the provided skill files do not justify those permissions.

Findings (2)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

If the user enters medication names or refill status, that information may appear in the generated printable card or caregiver note.

Why it was flagged

The skill may place medication or supply labels and refill status into the chat and printable card, which can reveal sensitive health routines even though this is purpose-aligned and privacy options are provided.

Skill content
Ask only for non-clinical tracking details... Item name, initials, category, or private label... Current refill concern
Recommendation

Use initials, generic labels, or private codes when privacy matters, and avoid adding full identifiers, insurance numbers, payment details, or protected medical records.

What this means

A user could be confused if the platform presents payment, wallet, or credential permissions for a skill that should not need them.

Why it was flagged

These high-impact capability signals do not match the prompt-only refill card purpose or the skill.json declarations of no credentials, no network, and no code execution; no included artifact shows actual use of those capabilities.

Skill content
Capability signals: crypto; requires-wallet; can-make-purchases; requires-sensitive-credentials
Recommendation

Verify the registry capability flags before installation and do not grant wallet, purchase, credential, pharmacy portal, or payment access for this skill.