This command is recorded from the source ecosystem and resolves the registry's latest release. The fixed release shown on this page should be inspected before adoption.
This automated, non-executing scan is bound to this release hash. It is not a safety certification and may contain false positives or false negatives.
Status
completed
Coverage
full text content
Files
2 / 2 inspected as text
Checked
8/28/2026, 11:22:40 AM
Scanner
0.1.3
Policy
1.0.3
1 inferred permission indicators
network access — automatically inferred
1 dependency and API indicators
api: clawhub.ai
External clawhub result: suspicious
This is registry-supplied evidence for the recorded release, not an independent SkillVetAI scan. Check the canonical source for the full report, scanner versions, scope, and current moderation state.
Evidence checked
8/28/2026, 7:23:03 AM
Release binding
Matches this record
skillspector: suspicious
llm: suspicious
Recorded files
The catalog stores hashes and an inventory summary for change detection. It does not republish the package contents.
Security review remediation (patch 2). Replaced the over-broad 'no-network / no-file / no-advice' disclaimer with an accurate, consistent capability statement: the skill is a methodology guide that does not bundle executable code or auto-run background tasks; the file I/O, API/MCP calls, audit logs and recommendations described in the body are user-executed in their authorized, compliance-governed environment. Added an explicit sensitive-data retention/access-control governance note and softened explicit operation-advice phrasing (e.g. buy-on-support / stop-loss). Resolves the SDI-1/SDI-4 capability-mismatch and SQP-2/SSD-3 data-control findings from the previous review.
Your privacy, your choice
Optional analytics and advertising services stay off unless you accept. Your choice is saved only on this device. Privacy Policy · Cookie Policy。
Global Privacy Control is enabled, so optional services will remain off.