Back to skill

Security audit

Smartclaws

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed SmartClaws onboarding guide with wallet and on-chain setup steps, but no hidden code or automatic actions were found.

Before installing, confirm you actually want SmartClaws onboarding. Treat wallet creation/import, sFUEL funding, role grants, backups, AGENTS.md adoption, and write-tool allowlisting as owner-controlled decisions, and do not place private keys or secrets in SMARTCLAWS.md or AGENTS.md.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The manifest description contains broad activation phrases such as 'start', 'set up', 'onboard', 'learn SmartClaws', and 'when it isn't configured yet', which can cause the skill to trigger in many loosely related conversations. Overbroad auto-activation increases the chance that an agent enters a high-privilege onboarding flow unnecessarily, exposing plugin/tool-discovery behavior and steering users toward wallet, plugin, and on-chain setup actions in contexts where that was not explicitly requested.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.