Back to skill
Skillv1.0.0
ClawScan security
Grants Program Marketing · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignApr 30, 2026, 4:56 AM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- The skill is an instruction-only guide for designing and marketing Web3 grants and its requirements and instructions are consistent with that purpose — it requests no credentials, installs no code, and does not ask the agent to access unrelated system data.
- Guidance
- This is an instruction-only marketing/operations guide that appears coherent and does not request credentials or install software. Before using: (1) review any messages or copy the agent generates before posting publicly or DMing communities, (2) do not provide private keys, wallet phrases, or treasury credentials to the agent, (3) validate recommended funding mechanics (on-chain disbursement, USDC vs token) with your treasury/legal teams, and (4) confirm outreach tactics comply with the rules of target communities (some servers disallow unsolicited posts). If you want higher assurance, inspect the full SKILL.md yourself for phrasing you might want to adjust to match your DAO's brand and compliance requirements.
Review Dimensions
- Purpose & Capability
- okName, description, and the SKILL.md content align: all modules describe program design, applicant acquisition, review, communications, and reporting. There are no unexpected required binaries, environment variables, or config paths.
- Instruction Scope
- okRuntime instructions are marketing/program-management guidance (copy templates, channel strategies, intake questions, review rubrics). They do not instruct the agent to read local files, access environment variables, or transmit data to external endpoints. The guidance includes recommending outreach to external communities and direct messages, which is appropriate for a marketing skill.
- Install Mechanism
- okThere is no install specification and no code files to write or execute; the skill is instruction-only, which minimizes installation risk.
- Credentials
- okThe skill declares no required environment variables, credentials, or config paths. No secrets or external service tokens are requested or referenced in SKILL.md.
- Persistence & Privilege
- okalways is false and the skill is user-invocable. It does not request permanent presence or system-wide configuration changes.
