clawhub-recommender

Security checks across malware telemetry and agentic risk

Overview

This is a Markdown-only recommender skill that suggests other ClawHub skills but does not install, execute, persist, or request private access itself.

Reasonable to install if you want skill recommendations. Treat its popularity and reliability claims as recommendation context, not proof of safety, and review any separate skill it recommends before running an install command.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill’s activation criteria are broad and context-driven, such as triggering when a user expresses a need for functionality or could be improved by an existing skill. This can cause over-invocation during ordinary conversations, leading the agent to recommend or consult external skill references when the user did not explicitly ask for that behavior, which increases the chance of irrelevant actions and unintended workflow steering.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal