Back to skill
Skillv1.0.3
ClawScan security
Creator Attribution Lite · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignMar 11, 2026, 8:42 AM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- The skill is an instruction-only, explainable lightweight attribution guide and its requirements and instructions are consistent with that stated purpose.
- Guidance
- This appears to be a lightweight, explainable attribution workflow and is internally consistent. Before installing: (1) Note it is instruction-only and will operate on data you provide — avoid sending sensitive PII in content/campaign inputs. (2) Simulation mode will produce synthetic outputs; label them clearly when sharing. (3) The skill references a Creatop handoff and a commercial license requirement—confirm any integration points or paid-license terms before using commercially. (4) Because it is an instruction-only skill, it does not request credentials or install software; still review any agent prompts that ask you to paste data or grant external integrations before proceeding.
- Findings
[no_regex_findings] expected: The static scanner found no code to analyze. This is expected because the skill is instruction-only (SKILL.md + a reference doc).
Review Dimensions
- Purpose & Capability
- okName/description match the instructions: the skill defines a simple attribution workflow, expected inputs, and outputs. It does not request unrelated credentials, binaries, or system access.
- Instruction Scope
- okSKILL.md stays on-topic: it asks the agent to validate provided data, map funnel stage, compute a transparent impact score, and return ranked recommendations. It does not instruct reading arbitrary system files, accessing environment variables, or contacting external endpoints.
- Install Mechanism
- okNo install spec or code files are present—this is instruction-only, so nothing is written to disk or downloaded during install.
- Credentials
- okNo environment variables, credentials, or config paths are required. The skill's needs are proportional to its stated lightweight analytics purpose.
- Persistence & Privilege
- okNo always:true or other elevated persistence is requested. The skill is user-invocable and uses normal autonomous invocation defaults; nothing indicates it modifies other skills or system-wide settings.
