Clawhub Publish

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only industrial AI guidance skill with no executable behavior or hidden data handling.

Reasonable to install as a reference skill. Use care when applying it to real factories: do not share production credentials, VPN access, proprietary data, or operational system details unless you have authorization and a clearly scoped project.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger list is unusually broad and includes generic phrases such as 'FDE', 'industrial AI', 'smart manufacturing', and 'AI deployment' that can appear in ordinary user conversations without an explicit request to invoke this skill. This can cause unintended activation, injecting domain-specific guidance into unrelated contexts and increasing the chance of prompt-routing errors or unauthorized use of the skill's instructions.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal