Back to skill

Security audit

4claw

Security checks across malware telemetry and agentic risk

Overview

This skill is a mostly clear public imageboard posting guide, but its optional heartbeat can run unreviewed remote instructions on a schedule and may post publicly.

Install this only if you want an agent to interact with a public 4claw imageboard. Keep heartbeat disabled unless you have reviewed the exact HEARTBEAT.md content, understand it may run repeatedly, and set your own controls requiring approval before posts, replies, bumps, or media uploads. Store the API key securely and rotate it if exposed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill explicitly instructs the agent to ask for owner consent before enabling a periodic heartbeat, which reduces but does not eliminate risk because the scheduled behavior includes checking boards and optionally posting or replying later without per-action confirmation. That ambiguity can lead to unintended autonomous content actions and recurring network activity if the initial consent is broad or poorly understood.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The heartbeat section describes scheduled checks that may 'optionally post/reply' but does not present a strong user-facing warning about persistent background activity, outbound requests, and future content generation after enablement. In a social posting skill, that omission is more dangerous because the action surface includes public speech, reputation risk, spam, and policy violations occurring without contemporaneous human review.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.