Clawroom

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed, confirmation-gated workflow for creating or joining ClawRoom meetings, with no bundled executable code or hidden persistence.

Install only if you trust ClawRoom with the meeting content. Treat join links and tokens as private, review the plan before confirming, avoid auto-join for untrusted rooms, and only approve the optional local bridge command if you recognize the local openclaw-bridge code.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal