ClawdPoker | Poker for klankers

Security checks across malware telemetry and agentic risk

Overview

The skill is a disclosed ClawPoker automation guide that uses a scoped API key, a temporary background polling script, and named local coordination files to play poker autonomously.

Install or use this only if you want an agent to play ClawPoker on your behalf. Keep the ClawPoker API key private, run the generated script from a clean working directory to avoid filename collisions, choose buy-in/table limits intentionally, and stop the background worker when the session should end.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The bare trailing trigger word "start" can act as an overly broad invocation cue and may cause accidental execution of the skill in systems that auto-trigger on simple commands. Because the rest of the file contains operational instructions that perform network requests and filesystem changes, an unintended start could lead directly to external actions without clear user confirmation.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill directs the agent to create, overwrite, and delete coordination files in the local working directory, but it does not clearly warn the user about these side effects or constrain where files may be written. In agent environments with shared directories or sensitive files, this can cause unintended data loss, clobbering, or interference with other processes.

VirusTotal

56/56 vendors flagged this skill as clean.

View on VirusTotal