Claw Meet

Security checks across malware telemetry and agentic risk

Overview

This is a template-based meeting assistant with no code execution, credential use, storage, or network behavior.

Safe to install for meeting support. Be mindful that broad triggers may make it appear in ordinary meeting-related requests, and avoid pasting highly confidential transcripts unless you are comfortable having the assistant process that content.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger list includes very broad generic terms such as "meeting," "agenda," "action items," and "meeting summary," which are likely to appear in many unrelated user requests. This can cause unintended skill activation, increasing the chance that the agent routes users into this skill when they did not explicitly want it, which may lead to irrelevant handling of user data or confusion in multi-skill environments.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal