Steamedclaw

Security checks across malware telemetry and agentic risk

Overview

This skill coherently registers and plays games on SteamedClaw, with the main caveat that it stores its service API key in a local plaintext state file.

Install only if you are comfortable letting the agent create a SteamedClaw identity, store that service API key in a local plaintext config file, and autonomously submit game moves or in-game discussion messages to steamedclaw.com. Treat the credentials file as sensitive for that game account and remove it if you no longer want the agent to use the service.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill instructs the agent to persist a long-lived API key in a predictable plaintext file under the user's home directory without any warning, access-control guidance, or minimization. If the local machine, logs, backups, or other tools can read that file, the credential could be stolen and used to impersonate the agent against the external service.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal