Back to skill
Skillv1.0.2
ClawScan security
Startup Financial Model · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignMar 17, 2026, 7:21 PM
- Verdict
- Benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- This is an instruction-only skill that provides step-by-step guidance to build startup 3-statement financial models and does not request extra credentials, install software, or perform out-of-scope actions.
- Guidance
- This skill is coherent and instruction-only: it will not install software or request credentials. Before using it, avoid pasting extremely sensitive credentials or unreduced personally identifiable data into the chat; if you need live accounting data, use a dedicated accounting-integration skill (e.g., qbo-automation) rather than copying credentials here. Review the generated formulas and outputs before sharing with investors, and ensure any exported spreadsheets do not include unnecessary confidential items. If you want the agent to run autonomously, remember it can generate models on its own prompts — review outputs and permissions in your agent settings if you prefer manual invocation.
Review Dimensions
- Purpose & Capability
- okThe name/description match the SKILL.md content: it provides guidance for revenue, expenses, P&L, cash flow, balance sheet, burn/runway and scenario modeling. There are no unrelated requirements (no credentials, binaries, or config paths) that would be disproportionate.
- Instruction Scope
- okAll runtime instructions are modeling-focused (inputs to collect, formulas, templates, scenario guidance). The SKILL.md does not instruct the agent to read local files, access environment variables, contact external endpoints, or exfiltrate data. It references other skills (qbo-automation, cap-table-manager) as alternatives, which is coherent.
- Install Mechanism
- okNo install spec and no code files (instruction-only). Nothing will be downloaded or written to disk by the skill itself.
- Credentials
- okThe skill declares no required environment variables, credentials, or config paths. The guidance does not require secrets or external API keys.
- Persistence & Privilege
- okalways is false and there's no indication the skill modifies agent/system settings or requests permanent presence. It follows normal user-invocable behavior.
