Back to skill

Security audit

ClawGuard

Security checks across malware telemetry and agentic risk

Overview

ClawGuard is a coherent security guardrail installer, but users should review its privacy settings because it can log tool calls, send tool context to an LLM, and collect anonymous metrics by default.

Install only if you trust @capsulesecurity/clawguard and are comfortable with a gateway plugin inspecting tool calls. In sensitive environments, disable full tool-call logging and metrics before production use, confirm which LLM provider receives evaluation context, and avoid sharing troubleshooting output that displays gateway tokens.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly documents that tool call details may be logged and that tool context is sent to an LLM for evaluation, but it does not present this as a prominent user warning before installation/use. This can lead operators to enable a plugin that forwards potentially sensitive prompts, arguments, file paths, or operational context to logs and an LLM provider without informed consent or data-handling review.

Missing User Warnings

Low
Confidence
87% confidence
Finding
The configuration table shows that anonymous usage metrics are enabled by default, but the skill does not clearly warn users of this behavior before installation. Even when described as anonymous, default telemetry can violate user expectations, internal policy, or regulated environment requirements if operators are not explicitly informed.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.