Back to skill

Security audit

Visual Architecture Clawhub V180

Security checks across malware telemetry and agentic risk

Overview

This skill is a local diagram-generation tool whose repo scanning and output files are disclosed and aligned with its purpose.

Install only if you want an agent to inspect a chosen local repository and generate diagram artifacts from it. Review generated HTML, SVG, JSON, receipts, and gallery files for private paths, hostnames, tokens, customer details, or internal architecture before publishing or sharing them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding
The skill instructs the agent to run local shell commands that read from the repository, write output files, invoke Python scripts, inspect git refs, and optionally call external tools. Because these capabilities are present but not explicitly declared in permissions, a caller or hosting platform may underestimate the skill's access level, increasing the risk of unintended file access, repository data exposure, or unsafe command execution in sensitive environments.

Missing User Warnings

Low
Confidence
87% confidence
Finding
The README encourages extracting repo evidence and generating bundles/gallery artifacts from the local repository, but it does not prominently warn that these outputs may embed or summarize sensitive internal structure and could be shared or published. In a skill explicitly designed to scan local codebases and produce reviewable artifacts, omission of privacy and disclosure guidance increases the chance of accidental data exposure through generated HTML, SVG, receipts, or gallery content.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.