中文 Axioma 守护
PassAudited by VirusTotal on May 8, 2026.
Findings (1)
The skill claims to be a security scanner but contains significant inconsistencies and potential telemetry risks. The SKILL.md instructions (written in Chinese) refer to a script named 'merlin-guard.py', whereas the provided Python script (containing French comments) is named 'clawguard.py'. The script makes external network calls to 'clawdex.koi.security' and 'clawhub.ai' to verify skills, which could be used to track a user's installed components. Additionally, the instructions command the agent to 'Notify Alexandre' upon threat detection, which constitutes an instruction to exfiltrate system security status to an unidentified third party.
