Back to skill
Skillv1.0.0
ClawScan security
Startup Guide · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignFeb 22, 2026, 11:42 PM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- The skill is an instruction-only Korean-language startup/business guidance router that delegates lookups to other government- and domain-focused skills; its declared requirements and instructions are consistent with its stated purpose.
- Guidance
- This skill appears internally consistent: it classifies startup-related intents and delegates data collection to other domain skills and public web searches. Before enabling it, check the reputation and permissions of the linked skills (company-info, tax-guide, law-search, korean-gov-programs, welfare-guide) because those delegated skills are the ones that may need API keys or access to official data sources. Note the publisher is unknown and there is no homepage — consider enabling in a limited/test environment first and verify that delegation paths (the referenced scripts and connectors) point to trusted, installed skills rather than arbitrary paths. Finally, remember the skill's outputs are informational only (it includes a disclaimer) and not a substitute for professional legal/tax advice.
Review Dimensions
- Purpose & Capability
- okName/description (창업/사업자 안내) match the content: intent routing, legal/tax/support lookups and delegation to company-info, tax-guide, law-search, korean-gov-programs, welfare-guide. It does not request unrelated credentials or binaries.
- Instruction Scope
- okRuntime instructions are limited to intent classification, delegating to other skills, running other skills' helper scripts (e.g., skills/*/scripts/*.sh or python collectors), and web_search for public info. There is no instruction to read arbitrary local system files, exfiltrate data, or post to unknown external endpoints.
- Install Mechanism
- okNo install spec or code to download/execute is included — this is instruction-only. No archives, external URLs, or package installs are requested.
- Credentials
- okThe skill declares no required environment variables, credentials, or config paths. It explicitly delegates API access (NTS/company-info, tax-guide, law-search) to separate skills rather than asking for secrets itself, which is proportionate to its router role.
- Persistence & Privilege
- okalways:false and user-invocable. The skill does not request persistent installation or system-wide changes and does not attempt to modify other skills' configs. Autonomous invocation is allowed by default but not combined with other elevated privileges here.
