Back to skill
Skillv1.0.0

ClawScan security

和君集团 · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignMar 11, 2026, 7:40 AM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
This is an instruction-only skill that contains marketing/about content for a consulting firm and does not request credentials, install anything, or instruct the agent to perform actions outside its stated purpose.
Guidance
This skill is essentially a static company profile and appears coherent with its stated purpose. Before installing, verify the publisher if you require provenance (owner ID differs from the company name and package.json author is 'LeoCryptoFlow'), and be cautious if future versions add environment variables, install steps, or code—those would require a fresh review. Also treat any external links in SKILL.md like any link: validate the URL independently before visiting or sharing sensitive data.

Review Dimensions

Purpose & Capability
okName/description (HeJun management consulting and investment services) match the included SKILL.md content. There are no unrelated requirements (no env vars, binaries, or config paths).
Instruction Scope
okSKILL.md is passive informational content (company overview, services, contact, website). It does not instruct the agent to execute commands, read files, or exfiltrate data.
Install Mechanism
okNo install spec and no code files beyond package.json and SKILL.md. Nothing will be downloaded or written to disk by an installer.
Credentials
okThe skill declares no environment variables, credentials, or config paths. No disproportionate access is requested.
Persistence & Privilege
okalways is false and the skill does not request persistent or elevated privileges or modify other skills or system settings.