VectorClaw MCP

Security checks across malware telemetry and agentic risk

Overview

This skill appears purpose-aligned, but it gives an AI real robot movement and camera access without enough upfront safety and privacy boundaries.

Install only if you intentionally want an agent to operate your Vector robot. Keep the robot in a safe, non-private area, require explicit confirmation before movement, speech, or camera capture, protect the robot serial and SDK certificate files, and verify the external Python package before enabling the MCP server.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The skill explicitly exposes camera/image capture capabilities (`vector_look`, `vector_capture_image`) but does not present a clear user-facing warning about privacy implications where capability is introduced. This can lead users to install or invoke the skill without understanding that it can capture visual data from the robot’s environment, increasing risk of inadvertent surveillance or collection of sensitive images.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal