Back to skill
Skillv1.0.1

ClawScan security

工业工程专家智体 · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignApr 29, 2026, 3:38 AM
Verdict
benign
Confidence
high
Model
gpt-5-mini
Summary
The skill is an instruction-only industrial engineering consultant: its requirements and runtime instructions align with its stated purpose and it does not request extra permissions or install code.
Guidance
This skill appears coherent and low-risk: it is instruction-only and asks for no credentials or installs. Before using, note the author/source is unknown (no homepage) — that affects accountability. When interacting, avoid pasting sensitive credentials or proprietary data into prompts, validate any operational changes on a small pilot before applying across production, and prefer explicit, structured data (metrics, layouts) so recommendations are actionable and auditable.

Review Dimensions

Purpose & Capability
okName/description (industrial engineering consulting) match the provided instructions and supporting docs; no unrelated environment variables, binaries, or installs are requested.
Instruction Scope
okSKILL.md and auxiliary files contain only guidance for asking questions, analyzing processes, and giving recommendations; they do not instruct the agent to read arbitrary files, access external endpoints, or exfiltrate data.
Install Mechanism
okNo install spec and no code files — instruction-only skill means nothing will be written to disk or downloaded during install.
Credentials
okNo environment variables, credentials, or config paths are requested; the declared footprint is minimal and proportional to a consultation skill.
Persistence & Privilege
okDefaults are used (not always:true). The skill is user-invocable and may be invoked autonomously by the agent per platform default, which is expected for a skill of this type.