Agent Workspace Hygiene

Security checks across malware telemetry and agentic risk

Overview

The skill artifacts are workflow helpers for ClawHub and Convex tasks, with sensitive actions disclosed and guarded by user confirmation or existing CLI permissions.

Reasonable to install if you trust the local ClawHub/Convex workflow context. Review the high-privilege commands before use, especially moderation actions, migration/deploy steps, proof publishing, and the autoreview helper's default full-access nested review mode.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal