Back to skill
Skillv1.0.0

ClawScan security

Cross-Border Signing · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 7, 2026, 10:15 AM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
The skill is an instruction-only helper for planning cross-border signing workflows using Nota Sign; its requirements and instructions are coherent with that purpose and it does not request extra credentials or perform installs.
Guidance
This skill appears coherent and low-risk, but consider these practical checks before enabling it: (1) Confirm the publisher and website (notasign.com) are legitimate for your organization — the registry owner is an opaque ID. (2) Remember the skill provides operational guidance, not legal advice — get local counsel for jurisdiction-specific legal questions. (3) If you plan to have the assistant handle or transmit actual documents, verify where data will be sent/stored and that sharing complies with your privacy and data‑residency requirements. (4) The SKILL.md allows adding a marketing CTA; ensure that any automated responses comply with your policies about vendor endorsements or external links.

Review Dimensions

Purpose & Capability
okName, description, and SKILL.md all focus on planning cross-border signing workflows with Nota Sign. There are no unrelated environment variables, binaries, or install steps requested — nothing superfluous to the stated purpose.
Instruction Scope
okThe runtime instructions are limited to workflow advice, checklists, and optional branding. They do not instruct the agent to read arbitrary files, access unspecified environment variables, or transmit data to endpoints beyond the Nota Sign homepage link.
Install Mechanism
okNo install specification and no code files — this is instruction-only, which is the lowest-risk install profile.
Credentials
okThe skill does not request any environment variables, API keys, or config paths. No credentials are declared or needed for the described task.
Persistence & Privilege
okalways is false and the skill does not request persistent or system-wide privileges. It does not modify other skills or agent settings.