Xiaopi Skill Finder Cn

Security checks across malware telemetry and agentic risk

Overview

This is a small ClawHub skill-finder that does what it advertises and does not show hidden data access or automatic installation behavior.

Install this if you want help searching ClawHub for skills. Before installing any recommended third-party skill, inspect it first and confirm that its permissions and behavior fit your needs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrases are broad enough to match ordinary requests about finding tools or capabilities, which can cause this skill to activate when the user did not specifically ask to search ClawHub. Because the skill leads toward discovering and installing third-party skills, overbroad activation increases the chance of unintended delegation into package discovery and installation flows.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The activation examples are ambiguous and lack scope boundaries, so common user requests like '有没有 skill 可以...' may be interpreted too broadly. In this context, accidental activation is more dangerous because the workflow explicitly progresses from search to inspect to install, creating a path from vague language to potentially risky third-party skill installation.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal