Back to skill
Skillv1.0.1
ClawScan security
TripSeek · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignMar 10, 2026, 1:52 AM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- The skill is an instruction-only travel planning assistant whose requested resources and instructions are consistent with its stated purpose.
- Guidance
- This instruction-only skill appears internally consistent for travel planning. It will likely ask you for personal travel details (names, passport/visa info, dates) which are normal for trip planning — only provide PII you are comfortable sharing. Because the skill has no homepage and no install code, it won't install software or request credentials, but exercise standard caution: do not paste sensitive account passwords or payment credentials into chat; if the agent proposes external booking/payment links, verify those endpoints before using them.
Review Dimensions
- Purpose & Capability
- okName, description, and included reference files all describe travel planning, itineraries, bookings, and family travel; there are no unrelated required binaries, env vars, or config paths that would be disproportionate to a travel-planning skill.
- Instruction Scope
- noteSKILL.md contains high-level workflow steps and local reference documents for planning and checklists; it does not instruct the agent to access system files, environment variables, or external URLs. Note: the skill will reasonably prompt users for personal travel details (passports, visas, traveler names) to perform its function — this is expected but involves PII supplied by the user.
- Install Mechanism
- okNo install spec and no code files — instruction-only — so nothing will be downloaded or written to disk during installation.
- Credentials
- okThe skill declares no required environment variables, credentials, or config paths. That is proportionate for a planning/consultation skill. Be aware that bookings or payments (not covered here) would require separate third-party integrations and credentials.
- Persistence & Privilege
- okalways is false and model invocation is allowed (platform default). The skill does not request persistent or elevated privileges and does not modify other skills or system settings.
