Back to skill

Security audit

Image To 3d

Security checks across malware telemetry and agentic risk

Overview

The skill bundle provides ClawHub and Convex maintainer workflows with powerful but disclosed commands, and I found no hidden or malicious behavior.

Install only if you intend to use ClawHub/Convex maintainer workflows and trust the local repo tools they call. Review the moderation and autoreview sections carefully: moderation commands can affect real users and skills, and autoreview can run nested review with broad local authority unless you opt out.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.