Back to skill
Skillv1.0.0

ClawScan security

Ai Food Recommendation Cn · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignMar 4, 2026, 3:46 AM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
The skill is an instruction-only Chinese food/recommendation assistant whose declared functionality matches the instructions and it requests no credentials or installs — nothing in the package is disproportionate to its stated purpose.
Guidance
This skill is instruction-only and appears internally consistent with its stated purpose. Before installing, consider: (1) origin: the source/homepage are unknown — verify the publisher if you require attribution or support; (2) privacy: the SKILL.md shows booking examples with contact data—do not provide real personal or payment details to an untrusted skill or channel unless you confirm it actually integrates with a legitimate booking service; (3) paid features: the pricing tiers are descriptive only — confirm how payments and API access are handled outside the skill. Overall it is low-risk as packaged, but verify the publisher and any live booking/payment integrations before sharing sensitive data.

Review Dimensions

Purpose & Capability
okName/description (AI food recommendations, reviews, bookings) align with the SKILL.md content: example recommendations, restaurant details, guides, and mock booking flows. The features and examples are consistent with a recommendation/chat assistant; there are no unexpected credentials, binaries, or system access requested.
Instruction Scope
noteSKILL.md is a content/instruction template with example outputs and booking mockups. It does not instruct the agent to read files, call external endpoints, or access system state. Note: the document includes booking examples (pre-filled contact/booking info) but provides no mechanism or credentials to perform real bookings — these appear to be illustrative rather than operational.
Install Mechanism
okNo install specification and no code files are present. Because this is instruction-only, nothing will be written to disk or installed during skill use.
Credentials
okThe skill declares no required environment variables, no primary credential, and no config path access. This is proportionate for a content-based recommendation assistant.
Persistence & Privilege
okalways is false and the skill is user-invocable with normal autonomous invocation allowed. The skill does not request elevated persistence or modify other skills or system settings.