LocalSquare - Local Business Ads
Analysis
This skill is coherently about buying a public LocalSquare ad pin, but it involves wallet signing, payment, and public business listing data that users should approve carefully.
Findings (5)
Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.
Checks for instructions or behavior that redirect the agent, misuse tools, execute unexpected code, cascade across systems, exploit user trust, or continue outside the intended task.
ALWAYS confirm with the user before making any payment.
The artifact documents a paid claim workflow and correctly gates it on explicit user confirmation, making the payment action purpose-aligned but still high-impact enough to notice.
Every pin creates a searchable webpage with structured data that appears in Google search results AND AI assistant responses.
A single claim can publish business information into search and AI-visible surfaces, which is intended for advertising but can be persistent and broadly visible.
This early adopter pricing won't last forever.
The artifact uses urgency-oriented promotional wording around a paid transaction; this is disclosed marketing language rather than hidden behavior.
Source: unknown; Homepage: none
The registry metadata lacks source and homepage provenance while the skill asks users to interact with an external payment-backed service.
Checks whether tool use, credentials, dependencies, identity, account access, or inter-agent boundaries are broader than the stated purpose.
Required capabilities: Crypto wallet with USDC on Base network (chain ID 8453), external wallet signing
The skill requires access to a wallet-signing flow that can authorize spending funds, even though it instructs users to keep private keys out of the agent.
