Security audit
Asr Claw
Security checks across malware telemetry and agentic risk
Overview
This is a speech-to-text skill whose executable download, local model setup, optional cloud transcription, and service controls are disclosed and fit its purpose.
Install if you want an agent-accessible speech recognition CLI. Verify the GitHub release and checksum before trusting the binary, use local engines for private audio, protect cloud API keys, and stop any local service engine when finished.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
