Clarity Fold Status

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a straightforward read-only status checker for Clarity Protocol.

Install this only if you are comfortable with it making requests to clarityprotocol.io. If you set CLARITY_API_KEY, treat it as a secret and prefer a scoped or revocable key; otherwise the skill can run as an unauthenticated read-only status checker.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding
The skill documentation indicates use of network access to clarityprotocol.io and reads the optional CLARITY_API_KEY environment variable, but the finding says no permissions are explicitly declared. Undeclared network and environment access weakens the security boundary because a host may allow the skill to run without clearly informing reviewers or users that it can exfiltrate environment-derived secrets or make outbound requests.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal