Claw-Net

Security checks across malware telemetry and agentic risk

Overview

This is a documented external data API integration; it uses an API key or paid x402 calls as described and shows no hidden or harmful behavior in the artifacts.

Before installing, confirm you trust ClawNet with the queries you submit, configure CLAWNET_API_KEY only for this service, and be cautious with sensitive business, wallet, or personal data because the skill relies on a remote API and may incur paid x402 or credit-based charges.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly instructs users to send natural-language queries and an API key to a third-party remote service, but it does not clearly warn that prompts, query contents, and authentication material are being transmitted off-platform. This creates a real privacy and data-governance risk, especially if users submit sensitive business, wallet, or market-intelligence data under the assumption processing is local.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal