Agent Workspace Hygiene
Security checks across malware telemetry and agentic risk
Overview
The skill artifacts are workflow helpers for ClawHub and Convex tasks, with sensitive actions disclosed and guarded by user confirmation or existing CLI permissions.
Reasonable to install if you trust the local ClawHub/Convex workflow context. Review the high-privilege commands before use, especially moderation actions, migration/deploy steps, proof publishing, and the autoreview helper's default full-access nested review mode.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
