Back to skill

Security audit

clawtributor

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed, approval-gated helper for drafting security incident reports, with no evidence of hidden execution or automatic data submission.

Before installing, understand that this skill may activate during general security-reporting requests and may help prepare reports containing sensitive evidence. Review and sanitize every report carefully, and only approve browser submission when you are comfortable sharing the exact contents with the maintainers.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger list includes highly generic phrases such as "report vulnerability," "security report," and "report incident," which are likely to match normal user requests unrelated to this specific skill. In agent environments where triggers influence automatic skill selection, this can cause the reporting skill to activate unexpectedly and steer sensitive security conversations toward preparing external-facing incident reports, increasing the risk of unintended data disclosure or workflow hijacking.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.