Security audit
Ai Culinary Arts
Security checks across malware telemetry and agentic risk
Overview
The reviewed ClawHub skill artifacts are high-authority internal workflow helpers, but their sensitive actions are disclosed, scoped, and guarded by confirmation or dry-run requirements.
Install only if you want ClawHub/Convex maintainer workflows in the agent. Some skills can guide admin actions, production migrations, outbound email, and external reviewer CLIs, so use them with authenticated accounts you trust and verify the shown commands before approving writes.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
