Back to skill
Skillv1.0.0
ClawScan security
Ontario Course Planning (OSSD) — Grades 9–12 + Top 6 (12U/M) · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignFeb 14, 2026, 9:55 PM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- The skill is an instruction-only course-planning assistant whose requested inputs and internal references align with its stated purpose and it does not request extra credentials, install code, or access beyond the included reference files and user prompts.
- Guidance
- This skill appears internally consistent and low-risk: it uses only the included course and rules documents and asks the user for required inputs. Before installing, confirm you are comfortable with the skill's web-search suggestions (it will recommend verifying program prerequisites on university sites). If you plan to persist changes to your local or shared catalog files, do so manually or after reviewing the proposed edits — the skill explicitly says not to overwrite files automatically during the chat. If you want extra caution, avoid granting any system-level file write access to the agent and only paste catalog/rules updates into the chat when you intend them to be used for planning.
Review Dimensions
- Purpose & Capability
- okThe name/description (Ontario course planning, Top 6 strategy) matches the runtime instructions and bundled reference files. There are no unrelated environment variables, binaries, or install steps requested — everything needed (course catalog, graduation rules, summer-school catalog) is present as included reference files.
- Instruction Scope
- okRuntime instructions are focused on: asking the user for inputs, reading and applying the included reference files, deriving prerequisites/Top 6 logic, producing/updating a 4-year plan, and recommending persistence of changes. The SKILL.md explicitly forbids overwriting included files in-place during chat. The instructions do suggest web searches to verify uncertain prerequisites — that is expected for this domain but means the agent may direct the user to external university pages for confirmation.
- Install Mechanism
- okNo install specification or code files are present; this is instruction-only. That minimizes risk because nothing is downloaded, written, or executed on the host by the skill.
- Credentials
- okThe skill requires no credentials, environment variables, or config paths. Its data needs are limited to the user-provided inputs and the local reference files bundled with the skill — proportional to the stated planning task.
- Persistence & Privilege
- okThe skill does not request always:true and is user-invocable with normal autonomous invocation allowed. It contains no install or write actions; maintenance guidance recommends the user persist changes into reference files manually. There is no evidence it modifies other skills or system-wide settings.
