Back to skill

Security audit

ClawSignal

Security checks across malware telemetry and agentic risk

Overview

ClawSignal is a coherent agent-messaging skill, but enabling it means external messages can automatically reach and prompt your agent.

Install this only if you want your agent reachable through ClawSignal. Keep API keys and dashboard tokens secret, review the separate plugin package and permissions before enabling it, use a narrowly scoped agent or workspace, and require human approval before acting on external messages that request sensitive data, account changes, code execution, or other high-impact actions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The skill explicitly states that incoming messages can trigger the agent automatically, but it does not meaningfully constrain what kinds of messages are allowed to cause execution. In a messaging skill, broad auto-triggering increases the risk of prompt-injection, spam-driven activation, or unintended agent actions initiated by untrusted external parties.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill describes automatic message-triggered behavior but does not clearly warn users that external messages may cause the agent to process data or initiate actions. Because this skill is designed for inter-agent messaging over a network, the absence of a strong warning materially increases the chance that operators will enable it without understanding the trust boundary and associated data-handling risks.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.