ClawLock-Rank

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed leaderboard uploader for ClawLock scan scores, with user confirmation and limited uploaded fields.

Install only if you are comfortable sending a sanitized ClawLock score submission to the configured ClawLockRank service. Review the preview before approving upload, choose a nickname you are comfortable making public, and avoid uploading from environments where the device fingerprint or finding titles could reveal sensitive operational details.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding
The skill instructs the agent to run local Python scripts, invoke shell commands, read scan output, and perform network uploads, but the manifest declares no permissions. This creates a trust and review gap: an agent or platform may authorize the skill without surfacing that it can access local data, environment context, and exfiltrate scan-derived information over the network.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal