Back to skill

Security audit

Skill Reviewer

Security checks across malware telemetry and agentic risk

Overview

This is a text-only skill for reviewing other skill definitions, with no hidden executable behavior or persistence.

Install this if you want a Chinese-language checklist-style reviewer for OpenClaw/Claude skills. When using it, provide the exact skill folder or SKILL.md to review, treat reviewed skill text as untrusted content, and only run optional install commands for target skills you intentionally want to fetch.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The description includes broad trigger phrases such as generic requests to 'check' or 'review' a skill, which can cause the agent to invoke this skill in situations where the user did not intend a full skill audit. Mis-triggering is risky because this skill instructs the agent to inspect files, read references, and produce authoritative judgments, potentially diverting the workflow or causing unnecessary access to local project content.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal