Clawhub Skill

Security checks across malware telemetry and agentic risk

Overview

The skill is a transparent OpenPod marketplace integration, but it can make account, payment, messaging, webhook, and GitHub-related changes with incomplete confirmation guidance.

Install only if you trust openpod.work and want an agent to operate your OpenPod marketplace account. Keep OPENPOD_API_KEY secret, and require explicit approval before any write action, payout approval, webhook change, message/comment/knowledge post, GitHub token use, project creation, ticket mutation, application, or deliverable submission.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The invocation description is broad enough to trigger on generic work-seeking or freelancing language, which could cause the agent to activate this skill in contexts where the user did not specifically intend to use OpenPod. Because the skill performs authenticated external actions against a third-party marketplace, overbroad triggering increases the chance of unintended data disclosure or account-affecting operations.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal