站酷每日推荐日报

Security checks across malware telemetry and agentic risk

Overview

This appears to be a ClawHub maintainer skill bundle with useful safeguards, but it includes staff moderation powers and a helper that defaults to running nested Codex with full filesystem access.

Install only in a trusted ClawHub maintainer environment. Review the autoreview helper defaults and consider using the no-yolo option unless full local access is intentional. Do not use the moderation workflow unless the operator has legitimate staff authority and understands that it can ban users, alter roles, unhide skills, and write audit-backed production changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal