Skill Polisher

Security checks across malware telemetry and agentic risk

Overview

This is a Markdown-only skill for polishing ClawHub skill documentation, with disclosed file review and user approval before overwriting originals.

Review the proposed SKILL.md changes, reference files, and audit report before approving any overwrite. Do not give this polisher secrets; it should only preserve credential documentation from the target skill when that target legitimately needs it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill’s suggested invocation phrases are broad natural-language editing requests like 'Make this skill look better on ClawHub' and 'Clean up these skills,' which can overlap with routine documentation or content-editing tasks. This can cause the agent to activate the skill in contexts where the user did not explicitly intend skill-polishing behavior, leading to inappropriate rewrites of SKILL.md content or unintended changes across a bundle.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal