Clawhub Publish 146256

Security checks across malware telemetry and agentic risk

Overview

This is a coherent article-illustration workflow that creates local prompt and image files for the requested article, with no evidence of hidden or destructive behavior.

Install this if you are comfortable with the skill creating an illustrations folder, saving article-derived prompts and images locally, and potentially sending prompt content to the image-generation tool you choose. Review prompts first for confidential articles.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill clearly instructs the agent to create directories, save outline and prompt files, generate image files, and insert image references into the article, but the top-level description does not warn users that it will write and modify workspace content. This can lead to unexpected file creation or edits, especially because the workflow includes blocking file operations and article modification as part of normal execution.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal