marsbit-news-skill

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward MarsBit news lookup integration that uses curl to contact a disclosed hosted endpoint.

Install only if you are comfortable sending MarsBit search terms and news IDs to www.marsbit.co. Prefer the ClawHub install path, and if using the GitHub fallback, review the repository before copying files into your OpenClaw skills directory.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Scope Creep

Medium
Confidence
94% confidence
Finding
The skill declares the "exec" tool even though its stated purpose is only to fetch hosted news and flash data. Granting command execution expands the attack surface significantly because any future skill logic or prompt-influenced behavior could invoke shell commands, making a read-only data skill capable of arbitrary local actions.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal