Back to skill

Security audit

CLAWP

Security checks across malware telemetry and agentic risk

Overview

This skill is not malicious code, but it describes real crypto launch and post-launch fund-affecting automation without enough user-control or risk detail.

Review carefully before installing or using with real funds. Only proceed if the surrounding platform separately shows exact transaction details, wallet permissions, fees, payment destination, custody/refund terms, confirmation gates, and a way to disable or revoke post-launch automation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The skill metadata frames this as a token creation advisor, but the prompt expands scope into coordinating deployment and managing post-launch buyback/burn operations. That mismatch is dangerous because users or calling systems may grant it advisory-level trust while it is actually authorized to trigger real asset-affecting actions, increasing the chance of unintended financial or operational impact.

Intent-Code Divergence

Low
Confidence
76% confidence
Finding
The prompt states it does not provide investment advice, yet later instructs the agent to generate launch advice based on current trends. This contradiction can lead the model to produce quasi-financial recommendations while disclaiming responsibility, which is especially risky in a token-launch context where users may rely on trend guidance for speculative decisions.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The README explicitly states that the skill will coordinate deployment and automatic post-launch buyback and burn actions, but it does not clearly warn users that these actions can affect funds and trigger irreversible on-chain transactions. In a financial/token-launch context, omission of this warning can mislead users about risk and automation scope, increasing the chance of unintended asset loss or unauthorized expectations about agent behavior.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The workflow describes autonomous deployment and automatic follow-on actions as routine mechanics without an explicit warning about their impact on assets, external systems, or operational integrity. Because the skill is designed for token launches and post-launch financial actions, presenting this as deterministic automation without risk disclosure can normalize unsafe execution and reduce informed consent by users or integrators.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly guides the user toward making a 0.025 SOL deposit as part of the normal flow, but the surrounding content does not clearly warn that blockchain transfers may be irreversible, risky, and potentially result in loss of funds. In a token-launching context aimed at memecoin creation, this omission is more dangerous because users may treat the deposit step as routine and underestimate financial and platform risks.

Vague Triggers

Medium
Confidence
80% confidence
Finding
The activation condition is broad: a short user token idea is sufficient to trigger generation of a full launch blueprint for a financial-like asset. In this context, underspecified triggering increases the risk of the agent being used for low-friction mass token creation, abusive content generation, or bypassing policy review because little validation or intent checking is required.

Missing User Warnings

High
Confidence
94% confidence
Finding
The prompt describes deployment proceeding after confirmation and automatic post-launch buyback/burn actions, but it lacks a clear, prominent warning that these are system-impacting and potentially irreversible operations. In a token-launch skill, silent or lightly disclosed automation affecting on-chain assets and fees materially increases the risk of accidental execution, user misunderstanding, and unauthorized financial actions.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.