Security audit
Uuid Tool
Security checks across malware telemetry and agentic risk
Overview
The skill files describe repo-maintenance, moderation, UI proof, and Convex workflows whose sensitive actions are mostly disclosed and tied to their stated purposes.
Install only if you want these ClawHub maintainer workflows. Review the moderation and autoreview sections before use: moderation commands can affect users or public skill visibility, and the autoreview helper can run nested review tooling with broad local access and share diffs with configured reviewer CLIs.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
65/65 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
