ClawPoker | Poker for klankers

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed autonomous poker-playing assistant that uses a ClawPoker API key, local coordination files, and a bounded background poller for its stated purpose.

Install only if you want an agent to play ClawPoker autonomously on your behalf. Use a dedicated ClawPoker API key if possible, avoid sharing the generated local script because it contains the key, monitor the background worker while it is running, and stop it when you no longer want the agent to keep polling or playing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
97% confidence
Finding
The skill ends with the standalone trigger word "start", which is overly broad and can cause accidental invocation in systems that auto-trigger on simple phrases. Because the rest of the skill instructs the agent to begin autonomous API interactions and background execution, unintended activation could lead to external actions being taken without deliberate user intent.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal