Back to skill

Security audit

Clawhub

Security checks across malware telemetry and agentic risk

Overview

This skill is for legitimate Android automation, but it gives an agent powerful phone-control and screen-reading abilities while under-disclosing privacy and state-change risks.

Review this carefully before installing. Use it only on devices you are authorized to control, avoid sensitive apps or screens unless necessary, confirm high-impact actions before execution, and review recorded workflows for private data or unintended reusable actions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Intent-Code Divergence

Medium
Confidence
96% confidence
Finding
The safety section makes a materially misleading claim that the skill will not access or modify sensitive data, but the documented capabilities include screenshots, UI-tree extraction, screen recognition, text input, app launching, and multi-device control. Those actions can expose message contents, account information, OTPs, and can also alter on-device state by sending messages, opening apps, or entering text.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The README promotes powerful Android automation capabilities including screen capture, UI analysis, text entry, app control, and workflow recording, but it does not warn users that these actions can access sensitive on-device data or trigger unintended changes. In the context of an MCP-connected AI skill, the absence of safety boundaries or consent guidance increases the risk of privacy exposure, accidental destructive actions, or misuse across one or multiple connected devices.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The activation examples are broad everyday requests such as viewing a screen, tapping, typing, or opening apps, without clear boundaries for confirmation or sensitivity checks. In a skill with direct device-control primitives, broad triggers increase the chance of unintended activation and unsafe execution on connected phones.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The tool descriptions for screenshot, recognizeScreen, and getUiTree omit privacy warnings even though these functions can capture and analyze highly sensitive on-screen information. Without clear disclosure, users may not understand that personal messages, credentials, financial data, or health information visible on screen can be exposed to the automation flow or connected models.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill documents text input, app launch, keypresses, taps, swipes, and multi-device concurrent execution without warning that these actions can be destructive or have external effects. They can send messages, change settings, trigger purchases, submit forms, or replicate harmful actions across many devices at once.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.