Back to skill

Security audit

Clawhub Memory Tiers

Security checks across malware telemetry and agentic risk

Overview

This skill is an instruction-only local memory helper, and its persistent workspace updates are disclosed and central to its purpose.

Install this only for agents where persistent local memory is desired. Keep L0.md and L1.md free of secrets, credentials, private personal data, and untrusted instructions, and review them periodically because future agent runs will rely on their contents.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill explicitly directs agents to modify L0.md and L1.md automatically at the end of every activation, which creates persistent side effects in the workspace without any user confirmation, opt-in guardrail, or conflict protection. In an agent setting, automatic writes can overwrite valid state, preserve prompt-injected content across runs, or cause integrity issues if the memory files are later trusted as authoritative context.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.