Clawhub Publish 146198

Security checks across malware telemetry and agentic risk

Overview

This skill automates job application form submission using disclosed local personal data and browser actions, which is sensitive but aligned with its stated purpose.

Install only if you are comfortable letting an agent submit job applications from your configured tracker and browser profile. Use a dedicated browser profile, review resume_ready entries and EEOC/contact values before running, and avoid storing or exposing passwords outside the browser's normal credential manager.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly supports login automation and form filling, which means it may collect, process, or submit sensitive credentials and other user-provided data. Without an explicit warning, consent boundary, and guidance on secure handling, an agent could use the skill to transmit secrets or perform account actions on the user's behalf without the risk being made clear.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal