Back to skill

Security audit

Clawmanager

Security checks across malware telemetry and agentic risk

Overview

This skill is a narrowly scoped job-fit and proposal drafting helper with no executable code, persistence, credential handling, or hidden data flows.

Install only if you want a dedicated assistant for Caleb's job-listing group or manually pasted job posts. Review generated proposals before sending, especially when the input is not clearly a structured job listing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger description is broad enough to activate on any pasted job posting or general request like 'should I apply,' which can cause the skill to run in situations where the user did not clearly request proposal generation or fit analysis. While not directly enabling code execution or data exfiltration, this increases the chance of unintended processing and misleading outputs based on incomplete or misclassified input.

Vague Triggers

High
Confidence
97% confidence
Finding
The instruction to treat every incoming group message as a job listing removes basic input validation and guarantees activation even when the content is not actually a job post. In an adversarial or noisy group context, this can be exploited to force the agent to mis-handle arbitrary messages, generate inappropriate recommendations or proposals, and normalize unsafe assumptions about untrusted input.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.