Back to skill

Security audit

CMO / Chief Marketing Officer

Security checks across malware telemetry and agentic risk

Overview

This CMO skill is a disclosed local-advice skill that stores scoped marketing preferences and memory locally, with human approval gates for money commitments and public statements.

Before installing, understand that this skill can keep local marketing context such as funnel numbers, channels tried, constraints, approval thresholds, and brand voice files in ~/Clawic/data/cmo/. Review or delete that folder if you do not want prior business context reused in later sessions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly instructs the agent to read from and write to user-local files containing preferences and business context, but it provides no user-facing notice or consent mechanism for that persistence. This can surprise users, create unintended retention of sensitive commercial data, and allow future runs of the skill to reuse or modify stored information in ways the user did not expect.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.