Back to skill
Skillv1.0.0

ClawScan security

Belgian Gaap Compliance Suite · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignMar 5, 2026, 9:13 PM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
The skill is internally consistent with its stated purpose: an instruction-only Belgian GAAP guidance bundle that requests no credentials or installs and contains no code — nothing in the package appears disproportionate or incoherent with the description.
Guidance
This package appears to be an offline, instruction-only Belgian GAAP guidance suite and is coherent with its description. Before installing or paying for the commercial bundle: (1) verify the publisher/author (mtllr) and any reviews or provenance since source/homepage are unknown; (2) test outputs with non-production or sample data to confirm accuracy of tax/accounting rules and regional specifics; (3) do not provide government or Intervat credentials to this skill unless the vendor explicitly documents a trusted, secure submission flow; (4) confirm how updates/bugfixes will be delivered for a commercial product; and (5) when in doubt about filing actions, treat this as an advisory tool and perform actual submissions through your established accounting software or government portal.

Review Dimensions

Purpose & Capability
okName, description, README, SKILL.md and bundle.yaml all describe an accounting/compliance guidance suite for Belgian GAAP and the listed components (PCMN, VAT, deductibility, Intervat, etc.) match that purpose. There are no declared external services, binaries, or credentials that would be unexpected for an accounting guidance skill.
Instruction Scope
noteSKILL.md is instruction-only and provides examples and usage scenarios; it does not direct the agent to read system files, access environment variables, or transmit data to external endpoints. Note: the Intervat/filing component is described but SKILL.md does not explain actual submission steps or required credentials — this is likely by design (guidance-only) but is a practical gap to be aware of.
Install Mechanism
okNo install spec and no code files — the lowest-risk format. bundle.yaml only documents metadata and install paths (e.g., ~/.claude/skills/...), which is informational; nothing is downloaded or written by the package itself in the provided files.
Credentials
noteThe skill declares no required environment variables or credentials, which is proportionate for an offline guidance/tooling skill. As a caution: real Intervat filing or automated submission to Belgian authorities would require credentials in practice; absence of such requirements here means the skill is guidance-only and will not perform authenticated submissions — confirm this behaviour before expecting automated filing.
Persistence & Privilege
okNo elevated privileges requested; always:false and no install hooks are present. The bundle metadata references typical per-user skill paths; the skill does not request persistent platform-wide privileges.