Startup Verifier

PassAudited by ClawScan on May 2, 2026.

Overview

This is an instruction-only startup evaluation checklist that uses external research sources, but it shows no code, credential access, persistence, or account-changing behavior.

This skill appears safe as an analytical checklist. Before installing, be aware that it may rely on external MCP/search sources, so do not include confidential startup details unless those services are trusted, and verify important market conclusions independently.

Findings (2)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

Startup details or research queries may be shared with external services, and untrusted external results could affect the GREEN/YELLOW/RED verdict.

Why it was flagged

The skill directs the agent to rely on another agent/service and an MCP API, and elsewhere to cross-check with external web sources. This is aligned with the market-research purpose, but the artifacts do not define the identity, permissions, or data-handling boundaries of those external integrations.

Skill content
Получить результаты от **Стратега** и **idea-reality-mcp API**
Recommendation

Use trusted external sources, avoid sending confidential startup information unless appropriate, and review cited evidence before acting on the verdict.

What this means

Users may have less clarity about exactly which documented version they are installing, but no hidden executable behavior is shown.

Why it was flagged

The provided registry metadata lists version 2.1.0 while _meta.json lists 1.0.0 and SKILL.md labels the verifier as v2.0. Because there is no code or install mechanism, this is only a release/provenance clarity issue.

Skill content
"version": "1.0.0"
Recommendation

Confirm the registry listing is the intended current release before relying on the skill for repeatable evaluations.