Back to skill

Security audit

Studying

Security checks across malware telemetry and agentic risk

Overview

This is a study-coaching skill with disclosed, narrow local preference storage; it does not show hidden, destructive, or unrelated behavior.

Before installing, check whether ~/studying/ or ~/clawic/studying/ contains anything unrelated that you do not want moved into the skill data directory. Otherwise, the local memory behavior is expected for a skill that personalizes study plans across sessions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly instructs the agent to read and migrate files in the user's home directory, including persistent preference and memory files, without any consent, disclosure, or minimization guidance. This creates an unnecessary local data access/modification path and could expose or alter sensitive user information beyond what is strictly needed for the study task.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.