Back to skill
Skillv0.1.9
ClawScan security
Residential Property Rolling Suds Estimator · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignApr 6, 2026, 2:17 PM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- The skill is an instruction-only estimator for residential exterior cleaning that asks for addresses and photos and uses public property data and the included pricing rules — its requirements and instructions are consistent with that purpose and it requests no credentials or system access.
- Guidance
- This skill is an instruction-only estimator that uses public property data and any photos you attach to produce a salesperson-friendly estimate; it asks for no credentials and has no install footprint. Before installing, consider: (1) only provide photos and addresses you are comfortable sharing (they may include personally identifying property details); (2) this tool produces estimates only — verify any quote before accepting or entering into Workiz; (3) because it's instruction-only, it won't add binaries or network endpoints, but confirm you trust the skill author/repo if you plan to use it in automated workflows; (4) if you need the agent to measure with Google Earth, that is a manual step the instructions recommend, not an automated data fetch. Overall the skill appears coherent and proportionate to its stated purpose.
Review Dimensions
- Purpose & Capability
- okName, description, and included pricing rules clearly match the runtime instructions: estimate exterior cleaning from an address, photos, and public property/listing data for a St. Louis-area service. The skill requests no unrelated binaries, environment variables, or config paths.
- Instruction Scope
- okSKILL.md stays within scope: it tells the agent to validate addresses, inspect attached exterior photos, consult public listing/map data, and apply the provided pricing rules. It does not instruct reading local system files, retrieving unrelated credentials, or sending data to unknown endpoints. It does recommend Google Earth as a human-run fallback for measurements (a reasonable, scoped suggestion).
- Install Mechanism
- okThere is no install spec and no code files — the skill is instruction-only, so nothing is written to disk and no external packages are fetched.
- Credentials
- okThe skill declares no required environment variables, no primary credential, and no config paths. All data sources referenced are public property/listing data or user-provided photos, which are proportional to the stated purpose.
- Persistence & Privilege
- okalways is false and the skill does not request elevated or persistent privileges. It is user-invocable and allows normal autonomous invocation (the platform default); nothing in the skill attempts to modify other skills or system-wide settings.
