Back to skill
Skillv2.0.0

ClawScan security

吴军投资智慧 · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignMar 20, 2026, 3:10 AM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
The skill's declared purpose (investment analysis using 吴军 principles) matches its instructions and resources; it requires no credentials, binaries, or installs and does not attempt unrelated access.
Guidance
This skill is internally consistent and requires no special permissions, but remember: (1) it provides generic investment analysis and is not a substitute for professional financial advice; verify any factual data (financials, market share, patents) against authoritative sources before acting; (2) do not paste sensitive or confidential company documents into the skill—only provide the non-sensitive fields the templates request; (3) confirm the authorship/trustworthiness of the packaged content if you need provenance (source/homepage is missing).

Review Dimensions

Purpose & Capability
okName/description and included SKILL.md, templates, and references consistently implement an investment-analysis assistant based on 吴军's ideas. There are no requested env vars, binaries, or unrelated dependencies that would be inconsistent with the stated purpose.
Instruction Scope
okRuntime instructions are self-contained: they ask for company/industry input and prescribe structured analyses (technology, data assets, market position, and recommendations). They do not instruct reading system files, environment variables, or contacting external endpoints beyond producing analysis text.
Install Mechanism
okNo install spec and no code files; this is an instruction-only skill so nothing is written to disk or fetched during install.
Credentials
okThe skill declares no required environment variables, credentials, or config paths. The data it requests (company_name, industry, tech/data/market info) is proportional to an investment analysis task.
Persistence & Privilege
okalways is false (no forced inclusion). disable-model-invocation is false (normal autonomous invocation allowed), which is expected for a user-invocable analysis skill and not combined with any broad credential access.