Back to skill

Security audit

Git

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only Git workflow skill whose repo-changing and preference-memory behavior is disclosed and aligned with its purpose.

Before installing, be aware that the skill can remember Git workflow preferences under ~/Clawic/data/git/ and can guide powerful Git operations such as force-pushes, history rewrites, hook setup, and credential cleanup. Review that memory directory if you do not want persistent Git preferences, and keep destructive Git actions under explicit review.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly instructs the agent to read and later write user-scoped files under `~/Clawic/data/git/` without requiring user notice or consent at the time of access or persistence. This creates a privacy and data-governance risk because personal preferences, habits, and prior context may be accessed or accumulated silently, potentially exceeding user expectations and exposing sensitive workflow information.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.