Back to skill
Skillv1.0.0
ClawScan security
和君集团 · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignMar 11, 2026, 7:40 AM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- This is an instruction-only skill that contains marketing/about content for a consulting firm and does not request credentials, install anything, or instruct the agent to perform actions outside its stated purpose.
- Guidance
- This skill is essentially a static company profile and appears coherent with its stated purpose. Before installing, verify the publisher if you require provenance (owner ID differs from the company name and package.json author is 'LeoCryptoFlow'), and be cautious if future versions add environment variables, install steps, or code—those would require a fresh review. Also treat any external links in SKILL.md like any link: validate the URL independently before visiting or sharing sensitive data.
Review Dimensions
- Purpose & Capability
- okName/description (HeJun management consulting and investment services) match the included SKILL.md content. There are no unrelated requirements (no env vars, binaries, or config paths).
- Instruction Scope
- okSKILL.md is passive informational content (company overview, services, contact, website). It does not instruct the agent to execute commands, read files, or exfiltrate data.
- Install Mechanism
- okNo install spec and no code files beyond package.json and SKILL.md. Nothing will be downloaded or written to disk by an installer.
- Credentials
- okThe skill declares no environment variables, credentials, or config paths. No disproportionate access is requested.
- Persistence & Privilege
- okalways is false and the skill does not request persistent or elevated privileges or modify other skills or system settings.
