Back to skill

Security audit

Hogwarts Magical Claw for Research Laboratory

Security checks across malware telemetry and agentic risk

Overview

This looks like a team-coordination skill, but it gives the agent recurring monitoring and public-notification behavior that is not scoped tightly enough for member privacy and sensitive project data.

Install only for a clearly opt-in team workspace. Before enabling heartbeat or chat posting, define approved channels, who can be tagged, what files may be read or updated, what data is never posted, retention limits for member records, and a human approval step for sensitive blockers, security issues, protected data, or unpublished research.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The meeting activation conditions are broad enough to match ordinary conversational words like '讨论一下' or '对齐', which can cause the agent to enter a structured meeting-host mode without clear user intent. In a team chat context, this can lead to unsolicited summaries, @mentions, and task orchestration that affect workflow and disclose or amplify discussion content unnecessarily.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The HEARTBEAT workflow says it runs every 30 minutes but does not define the execution authority, scope, or guardrails for when autonomous checks are permitted. That ambiguity increases the chance of the agent repeatedly scanning files and initiating outreach without a fresh user request, creating unnecessary monitoring and potentially disruptive autonomous behavior.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill directs the agent to read and update member communication records and progress files on a recurring basis, but it does not warn about consent, minimization, retention, or sensitivity of the stored activity data. In a research team environment, those records may contain behavioral, performance, and potentially personal information, so routine collection and modification without privacy controls is risky.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The protocol instructs the agent to post progress summaries to a team chat channel after commits, but it does not require review, minimization, or sensitivity checks before disclosure. In a research-team context, summaries can easily include unpublished results, internal task status, or personal/member-related details that should remain scoped to the repository or designated stakeholders.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
This section directs the agent to notify or tag members when blockers are detected, including from internal logs and task updates, without guardrails for privacy, accuracy, or social/workflow impact. Automated escalation based on inferred status can expose personal productivity patterns, create false accusations of delay, or disclose internal project risks more broadly than intended.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The HITL workflow requires posting help requests through issues and team chat, but it lacks safeguards to prevent sensitive context from being copied into those channels. Because HITL triggers explicitly include protected data, security issues, and unpublished results, this procedure can turn a safety escalation into a secondary data-leak path.

Ssd 3

Medium
Confidence
96% confidence
Finding
Persistently logging member contact frequency and proactively calling out individuals in group chat can create avoidable surveillance and repeated disclosure of work-status data. In a collaborative academic setting, this may pressure users, expose inactivity patterns to others, and normalize excessive monitoring beyond what is needed to coordinate work.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.