Back to skill
Skillv1.0.1
ClawScan security
assistant · ClawHub's context-aware review of the artifact, metadata, and declared behavior.
Scanner verdict
BenignMay 1, 2026, 7:27 AM
- Verdict
- Benign
- Confidence
- high
- Model
- gpt-5.5
- Summary
- This is a code-free bilingual product Q&A skill with static reference documents and no evidence of hidden actions, credentials, or data access.
- Guidance
- Before installing, confirm that the PalmAI/KYC reference content is accurate for your product and customer context. From the provided artifacts, this skill appears limited to bilingual product-answer assistance and does not request system access or credentials.
Review Dimensions
- Purpose & Capability
- okThe stated purpose is to help product architects answer overseas customer questions, and the included reference files are product FAQ and KYC Standard documentation that align with that purpose.
- Instruction Scope
- okThe instructions define response language and business-answering style only; they do not request tool use, privileged actions, credential handling, or unsafe autonomy.
- Install Mechanism
- okThere is no install specification and no code files, so the artifacts do not show package installation, downloaded helpers, scripts, or executable behavior.
- Credentials
- okThe skill declares no binaries, environment variables, credentials, config paths, or OS-specific access, which is proportionate for an instruction-only Q&A assistant.
- Persistence & Privilege
- okAlthough the wording references knowledge accumulation, the provided artifacts show only static reference documents and no mechanism for persistent memory writes, background activity, or privilege escalation.
