Back to skill
Skillv1.0.1
ClawScan security
外贸业务全能助手 · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignMar 26, 2026, 8:42 AM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- This is an instruction-only skill that provides templates and guidance for export/trade tasks and does not request credentials, install code, or access system resources.
- Guidance
- This skill is a collection of templates and guidance for export business communications and procedures and appears self-contained. Before using it: don't paste sensitive customer data or credentials into prompts, review and adapt templates for legal/compliance requirements (incoterms, payment terms, data privacy), and avoid configuring any automation that would send emails or transmit customer data without explicit review. If you plan to engage the listed contact for paid services, verify the provider independently.
Review Dimensions
- Purpose & Capability
- okThe skill's name and description promise a one-stop guide for export business tasks (emails, quotes, contracts, logistics, disputes). The provided SKILL.md only contains templates and process guidance, which aligns with that purpose. There are no unrelated environment variables, binaries, or install steps requested.
- Instruction Scope
- okRuntime instructions are purely templates, sample text, negotiation tips, and workflow steps. The SKILL.md does not instruct the agent to read local files, access environment variables, contact external endpoints programmatically, or transmit data outside the conversation. It only includes an author contact email for paid services, which is external but optional and visible to the user.
- Install Mechanism
- okNo install spec and no code files are present. As an instruction-only skill, it writes nothing to disk and installs nothing, which is the lowest-risk model.
- Credentials
- okThe skill does not request any environment variables, credentials, or config paths. There are no secrets or unrelated credentials required for its stated functionality.
- Persistence & Privilege
- okalways is false and the skill is user-invocable; disable-model-invocation is false (normal). There is no indication the skill modifies agent configuration or asks for persistent access. Autonomous invocation is allowed by default but this skill's content is passive templates, so risk from autonomous runs is low.
