Ergonomic Bag Pack Check

Security checks across malware telemetry and agentic risk

Overview

The skill text is a harmless prompt-only bag comfort checklist, but its capability signals unexpectedly mention wallet and sensitive credential access that do not fit the stated purpose.

The written skill appears to be a simple no-code checklist for making a bag more comfortable, but the registry capability signals do not match that purpose. Before installing, verify that it truly requests no wallet, credential, network, or execution permissions; if any sensitive-access prompt appears, do not grant it.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Risk analysis

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

#
ASI03: Identity and Privilege Abuse
Medium
What this means

If the platform actually grants or prompts for these capabilities, the skill could receive access that is unrelated to the bag audit task.

Why it was flagged

These signals indicate wallet or sensitive credential capability, which is not justified by an instruction-only skill for auditing backpack or daily-carry comfort.

Skill content
- crypto
- requires-wallet
- requires-sensitive-credentials
Recommendation

Install or use this skill only if the platform confirms it does not request wallet access, secrets, API keys, or other sensitive credentials; deny any such prompt.