Back to skill

Security audit

Claw Messenger

Security checks across malware telemetry and agentic risk

Overview

The skill appears to do what it claims, but it gives an agent real texting access and live credential handling without enough privacy, approval, or secret-handling safeguards.

Review before installing. Use a dedicated revocable API key, avoid pasting live keys into chat when possible, restrict inbound messaging with pairing or allowlists, require human confirmation for outbound messages and media, monitor billing, and avoid sensitive or regulated conversations unless the provider's privacy and retention practices meet your needs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly instructs the agent to ask for a live API key and place it into a local configuration file, but it does not warn that this is a sensitive credential or provide guidance on secure handling, redaction, storage, or scope minimization. In an agent context, this increases the chance the key is exposed in chat logs, prompts, screenshots, repositories, or other tooling, enabling unauthorized use of the messaging account and access to messaging capabilities.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The documentation says messages are sent and received through shared infrastructure, but it does not clearly warn that message bodies, attachments, phone numbers, routing data, and related metadata transit and may be processed by a third-party service. In a messaging skill, this omission is security-relevant because agents or users may send sensitive personal, business, or regulated data without informed consent or an understanding of the privacy boundary.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal