Back to skill

Security audit

Claw Trace

Security checks across malware telemetry and agentic risk

Overview

This appears to be a trace/debugging skill, but its persistent trace controls are too easy to activate and could expose sensitive tool inputs or outputs.

Install only if you intentionally want trace visibility into agent tool activity. Prefer session-only tracing, avoid full or auto-display modes around secrets, review any save-to-file behavior, and use explicit commands or confirmations for configuration changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill advertises broad natural-language triggers such as enabling features or switching modes without requiring a clearly scoped command format. In a conversational agent, generic phrases can be matched accidentally during ordinary discussion, causing unintended trace activation or configuration changes that may expose tool inputs/outputs more broadly than the user intended.

Vague Triggers

Medium
Confidence
97% confidence
Finding
The listed user commands are overly generic (for example, "enable trace", "use full mode", and filter phrases) and directly mutate persistent configuration. Because this skill can automatically display trace output after every tool call when enabled, accidental or prompt-injected activation could increase disclosure of sensitive operational data, especially if redaction is incomplete or bypassed.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.