Cc

Security checks across malware telemetry and agentic risk

Overview

The skill appears to do what it claims, but it lets remote chat messages drive a persistent local Claude Code session and stores session output locally without clear upfront disclosure.

Install only if you intentionally want an OpenClaw channel such as Telegram, Discord, or CLI to control your local Claude Code session. Use it in private channels, avoid sending secrets, choose project roots carefully, check active sessions with /cc status, and stop sessions with /cc off so the tmux session and local log are cleaned up.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly enters a mode where all subsequent user messages are forwarded to an external/local Claude Code session, but it does not require an explicit privacy or data-transmission warning at the point relay mode starts. In practice, users may continue chatting as if they are speaking to the current assistant, unintentionally sending sensitive data, credentials, or private project details into another tool context.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal