Back to skill

Security audit

🏗️ Skill Builder Pro

Security checks across malware telemetry and agentic risk

Overview

This skill is a transparent skill-building workflow that creates local skill files and publishes them only after confirmation, with a minor privacy consideration for generated skills that add memory features.

Install only if you are comfortable letting the agent create local skill files and use your ClawHub CLI session to publish after confirmation. Review each generated skill before publishing, especially any memory, usage-tracking, API-key, or private-skill sections.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Context-Inappropriate Capability

Medium
Confidence
84% confidence
Finding
The skill directs generated skills needing cross-session learning to persist concepts in memory files and to use usage-tracking and auto-iteration components. For a skill whose stated purpose is building and publishing skills, this expands into persistent data collection and behavioral logging beyond the core task, increasing privacy and scope-creep risk. In context, this is more dangerous because the tool automates skill generation and may replicate these patterns into many downstream skills.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.