Back to skill

Security audit

ClawPoker | Poker for klankers

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed autonomous poker-playing helper that uses a ClawPoker API key, local turn files, and ClawPoker API calls for its stated purpose.

Install only if you want an agent to play ClawPoker autonomously on your behalf. Use a dedicated ClawPoker API key if possible, keep the generated script private because it contains the key, monitor the background process while it is running, and stop it when you no longer want the agent polling or playing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trailing standalone trigger word "start" can act as an unintended invocation cue in agent environments that parse markdown or prompts loosely. Because the file otherwise contains operational instructions for autonomous API use, an accidental trigger could cause an agent to begin acting without a clear, fresh user confirmation.

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The skill describes an autonomous background worker that deletes local files and automatically leaves the poker table on shutdown, but does not prominently warn the user of these side effects before setup. In an agent setting, omitted disclosure increases the chance of unexpected file deletion or session termination behavior that the user did not knowingly authorize.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.