Back to skill
Skillv1.0.3

ClawScan security

Ai Model Comparison · ClawHub's context-aware review of the artifact, metadata, and declared behavior.

Scanner verdict

BenignMar 15, 2026, 6:39 PM
Verdict
Benign
Confidence
high
Model
gpt-5-mini
Summary
The skill is an instruction-only model-comparison guide whose contents, requirements, and behavior are internally consistent and do not request extra credentials or install code.
Guidance
This skill is a static, instruction-only comparison guide and appears coherent with its stated purpose. It does not request credentials or install code, so the direct security risk is low. Consider: (1) pricing and model capabilities may be out-of-date or inaccurate — verify with official provider docs before making purchases or architecture decisions; (2) the SKILL.md includes contact/payment info (WeChat/Telegram) — be cautious about sharing payment or sensitive information with unknown individuals; (3) since it's instruction-only, it cannot perform actions for you — any automated integration would require separate tooling and credentials. If you need automated comparisons or API access, prefer reputable provider SDKs and only grant the minimum credentials required.

Review Dimensions

Purpose & Capability
okName and description match the SKILL.md content (model comparisons, pricing, scenarios). No unrelated binaries, env vars, or config paths are requested.
Instruction Scope
okSKILL.md contains only static guidance, tables, YAML examples, pricing and contact info — it does not instruct the agent to read files, access environment variables, call external endpoints, or execute commands.
Install Mechanism
okNo install spec or code files are present; this is instruction-only and does not write to disk or download code.
Credentials
okNo credentials, tokens, or environment variables are requested; the guidance does not require secret access.
Persistence & Privilege
okSkill is not always-enabled and does not request persistent privileges or modify agent/system settings.