MaxClaw Helper

Security checks across malware telemetry and agentic risk

Overview

This skill is a documentation and troubleshooting helper for MaxClaw/OpenClaw with no executable code or hidden install behavior.

Safe to install for MaxClaw/OpenClaw help. Use it for product-specific questions and troubleshooting, but avoid pasting tokens, passwords, private config values, or sensitive logs into prompts that may be used for external documentation lookup.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger list is extremely broad and includes common phrases like 'can I', 'is it possible', 'help me set up', and generic troubleshooting language. This can cause the skill to activate in many unrelated conversations, increasing prompt-surface exposure and the chance that the skill overrides more appropriate skills or injects irrelevant operational guidance into sensitive workflows.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal