Back to skill

Security audit

Test Skill from TPClawHub

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a placeholder test skill with no executable code, but its setup instructions are too vague for real credential use.

Treat this as a test or placeholder skill. Do not provide an API key unless the publisher documents what service it is for, what permissions it needs, how it is stored or used, and what script or dependency will consume it.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.