Back to skill

Security audit

Pharmaclaw Catalyst Design

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a chemistry design helper with an IP-analysis handoff, and the available evidence does not show hidden execution, credential use, destructive behavior, or exfiltration.

Before installing, confirm whether IP Expansion is automatic or user-confirmed, and avoid using confidential unpublished chemistry unless you are comfortable with that data being included in the skill's outputs or downstream analysis.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The manifest uses very broad chemistry-related trigger terms like catalyst, ligand, phosphine, and reaction conditions without clear scope limits, which can cause the skill to activate in contexts beyond the intended workflow. In an agent ecosystem, overbroad triggering can lead to unnecessary execution, unintended access to chemistry/IP workflows, and propagation of sensitive research inputs into downstream systems.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The description states that outputs feed into IP Expansion for patentable inventions, but it does not clearly warn users that ligand designs may be automatically forwarded into a patent/IP workflow. This is dangerous because proprietary chemistry ideas, novel structures, or confidential R&D prompts could be transmitted to downstream components without informed consent or clear disclosure.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.