Quantum Tech

Security checks across static analysis, malware telemetry, and agentic risk

Overview

This skill appears to be a straightforward quantum-career roadmap tool, with only expected collection of career assessment details and minor provenance uncertainty.

This looks safe for its stated purpose. Before using it, confirm you are comfortable sharing career background, skills, goals, session identifiers, and optional user ID with an unknown-source service.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Risk analysis

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

#
ASI07: Insecure Inter-Agent Communication
Low
What this means

Using the roadmap endpoint may share your skills, experience, goals, session ID, timestamp, and optional user ID with the service.

Why it was flagged

The OpenAPI schema defines a POST endpoint that receives user assessment information to generate a roadmap.

Skill content
"/api/quantum/roadmap": { "post": { ... "Generate personalized quantum technology roadmap" ... "RoadmapRequest" } }
Recommendation

Only provide information you are comfortable sharing with the service, and avoid including sensitive personal details beyond what is needed for career guidance.

#
ASI04: Agentic Supply Chain Vulnerabilities
Info
What this means

You have less information to verify who operates or maintains the skill and its API.

Why it was flagged

The supplied registry metadata does not identify a source repository or homepage for independent provenance review.

Skill content
Source: unknown; Homepage: none
Recommendation

Prefer installing only if you trust the publisher or can otherwise verify the service before sharing career-profile data.