defense draft

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a narrow legal-document drafting helper with no evidenced credential use, network access, persistence, or account-changing behavior, though users should verify its source before running included helper code.

This looks appropriate for drafting a framework, not for replacing legal counsel. Be careful with personal case details, verify court deadlines with a qualified attorney, and avoid running included scripts unless you trust the package source.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Risk analysis

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

#
ASI04: Agentic Supply Chain Vulnerabilities
Info
What this means

If a user chooses to run the included helper scripts, they should be comfortable with the package source.

Why it was flagged

The registry-level source provenance is not resolved, while the package includes JavaScript files that could be run manually. The provided code and instructions do not show suspicious behavior, but users should verify provenance before executing included helpers.

Skill content
Source: unknown; Homepage: none
Recommendation

Use the skill as an instruction/template helper; only run the JavaScript files if you trust the package source or have reviewed the code.