Claw MBTI

Security checks across malware telemetry and agentic risk

Overview

This is a personality quiz skill that calculates a result and creates an external results link, with a privacy consideration because the link contains the inferred personality scores.

Before installing, understand that this skill asks personal behavioral questions and produces an external result link. Treat that link as profile data: it includes your inferred MBTI type and percentage scores, so avoid opening or sharing it if you do not want that information visible to the external site or anyone who sees the URL.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill instructs the agent to generate and share a result URL that encodes the user's personality assessment in query parameters. That creates an unnecessary privacy leak because personality traits are sensitive profiling data and may be exposed via chat logs, browser history, referrers, link previews, analytics, or third-party services without user consent.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal