Back to skill

Security audit

React

Security checks across malware telemetry and agentic risk

Overview

This React guidance skill is coherent and purpose-aligned, with a limited disclosed local memory/config migration note but no evidence of hidden or harmful behavior.

Before installing, be aware that the skill may create or reuse local React preference files under ~/Clawic/data/react/. If you already have data in ~/react/ or ~/clawic/react/, review it before migrating so nothing important is overwritten. The React project setup commands should only be run in projects where you intend to scaffold or install those dependencies.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Context-Inappropriate Capability

Low
Confidence
90% confidence
Finding
The skill directs the agent to move files within the user's home directory (`~/react/` or `~/clawic/react/` to `~/Clawic/data/react/`) even though the skill is primarily an advisory React development guide. Any instruction to modify user files outside the immediate task scope creates unnecessary risk of unintended data movement, overwriting, or privacy-impacting access, especially if executed automatically without confirmation. The 'verified skill library' language should not reduce scrutiny.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.