Back to skill
Skillv1.0.0
ClawScan security
Brand Naming · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignMar 24, 2026, 6:35 PM
- Verdict
- benign
- Confidence
- high
- Model
- gpt-5-mini
- Summary
- An instruction-only brand-naming helper whose content, requirements, and instructions are consistent with its stated purpose and request no credentials or installs.
- Guidance
- This is a low-risk, instruction-only skill that provides naming guidelines, templates, and pointers for domain/trademark checks. Before installing: 1) Note the skill has no homepage and an unknown source—content is harmless but consider whether you trust the publisher. 2) The skill does not itself perform live domain or trademark queries; if the agent has web access it could run lookups—confirm your agent's browsing/network policy. 3) Always independently verify domain availability and trademark clearance through official registries before committing to a name. 4) Avoid sending highly sensitive or proprietary business plans in prompts; the skill is meant for creative naming and evaluation, not secure handling of secrets.
Review Dimensions
- Purpose & Capability
- okName, description, and runtime content all focus on generating and evaluating brand names, domain and trademark checks. There are no environment variables, binaries, or config paths requested that don't fit the stated purpose.
- Instruction Scope
- noteSKILL.md contains templates, evaluation criteria, domain and trademark resources — all within scope. It mentions domain/trademark checking but provides no automated queries or external endpoints; if the agent has web access it could perform live checks, which is expected but not specified by the skill.
- Install Mechanism
- okNo install spec and no code files (instruction-only). Nothing will be written to disk by the skill itself.
- Credentials
- okThe skill requests no environment variables, credentials, or config paths. There are no disproportionate secret requests.
- Persistence & Privilege
- okFlags are default (not always). The skill is user-invocable and can be invoked autonomously (platform default) but does not request persistent or elevated privileges.
