🇯🇵🇰🇷 日韩市场政策查询Skill

PassAudited by ClawScan on May 10, 2026.

Overview

This is an instruction-only policy lookup skill with no code or install-time access, but users should notice an opaque auto-calibration claim and a conflicting credential capability signal.

This skill appears safe to install as an instruction-only policy-query helper. Before using it for compliance decisions, verify results against official sources, and do not provide credentials if it unexpectedly asks for them.

Findings (2)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

The skill may influence how the agent formats or prioritizes answers, but there is no artifact evidence that it executes code or accesses data during calibration.

Why it was flagged

The skill advertises an automatic calibration step, but the artifacts do not explain or implement it. This is not shown to be harmful, but users should not treat the undefined calibration framework as extra authority or safety assurance.

Skill content
本Skill搭载惠迈校准框架v1.0。首次加载自动执行快速校准。
Recommendation

Treat the calibration wording as a response-style claim only; do not grant extra permissions or trust based on it.

What this means

If the skill unexpectedly asks for tokens, cookies, API keys, or account login later, that would go beyond the visible instructions.

Why it was flagged

The declared requirements say no credentials are needed, while the capability signal indicates sensitive credentials. The provided files do not show credential collection or use, but the mismatch is worth checking.

Skill content
Required env vars: none; Primary credential: none; Capability signals: requires-sensitive-credentials
Recommendation

Do not provide credentials unless the skill clearly explains which credential is needed, why it is needed, and how it will be used.