Back to skill

Security audit

Skill Audit & Publish

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed publish-prep workflow that emphasizes sanitization, staging, and explicit approval before anything is uploaded.

Before installing, understand that this skill is meant to help publish skills publicly. Review the generated publish folder, the sanitization keep-list, and the final slug/name/version/files carefully before approving any ClawHub publish command.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
The file explicitly requires every transformed skill to end with a Chinese summary, framing it as a retrieval optimization rule rather than an optional or region-specific feature. This imposes a specific language/locale choice on output without offering user choice or documenting a compliance-based need.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.