vizclaw

Security checks across malware telemetry and agentic risk

Overview

VizClaw is a disclosed visualization bridge that sends run events to VizClaw, with privacy and supply-chain cautions users should understand before use.

Install only if you are comfortable sending OpenClaw run activity to VizClaw. Use overview mode for sensitive sessions, do not stream secrets, prefer the ClawHub-installed artifact over unpinned remote `uv run`, and avoid using gateway tokens over non-local or non-TLS WebSocket endpoints.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding
The skill documentation instructs users to run a remote Python script directly from a URL and states that events auto-stream to an external service, which implies network access and likely local data access without any declared permissions. This creates a transparency and consent gap: users may install or run the skill expecting normal visualization behavior while unintentionally granting a remote component access to run data, prompts, tool outputs, or local files processed by the agent.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal