Security audit
landing-page-generator
Security checks across malware telemetry and agentic risk
Overview
The available scan inputs show no issues, but the actual target skill artifact was not identifiable in the workspace for a full artifact review.
Based on the available telemetry, there is no reason to hold this skill for review. Because the target artifact files were not available for direct inspection, users should still check the ClawHub file listing and metadata before installing, especially for any declared credentials, command execution, or broad filesystem access.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
58/58 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
