claw://Meetup

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only meetup finder whose location search, optional reminders, and sharing help are disclosed and approval-gated.

Safe to install for event discovery. Before enabling ongoing tracking or reminders, confirm the exact city/radius, what will be stored, and what reminder or background check will run.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The help template includes broad trigger examples such as 'events near me' and 'show me the best option', which are common conversational requests that could cause this skill to activate when the user did not specifically intend to invoke meetup functionality. In an agent environment, overly generic trigger phrases increase the chance of incorrect routing, unintended data collection about location/preferences, or the skill taking action in the wrong context.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal