Pharmaclaw Pharmacology Agent

Security checks across malware telemetry and agentic risk

Overview

This skill is a local RDKit-based molecule profiling helper with no evidence of hidden access, persistence, credential use, network exfiltration, or destructive behavior.

Install only if you are comfortable running the bundled local Python script and have a trusted RDKit setup. Use the results for research triage only; do not rely on its ADME, toxicity-adjacent, interaction, BBB, or bioavailability estimates for medical, clinical, regulatory, or safety-critical decisions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The agent returns pharmacology and ADME predictions as structured results with confidence values but no prominent disclaimer that they are heuristic, rule-based estimates not suitable for medical, clinical, or safety-critical decision-making. In a pharmacology context, this increases the risk that users or downstream agents over-trust the output and make hazardous decisions about bioavailability, BBB penetration, metabolism, or interaction risk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal