Back to skill

Security audit

Clawhub

Security checks across malware telemetry and agentic risk

Overview

The skill is a coherent GPU/cloud instance helper, but it gives an agent billable provisioning, raw remote command execution, and destructive instance deletion without strong confirmation boundaries.

Install only if you intend to let the agent manage JarvisLabs GPU resources. Before use, require explicit approval for every create, resume, storage change, raw exec command, public port exposure, pause, or destroy action, and monitor billing so instances are not left running unintentionally.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description is very broad and invites use for generic requests like 'deploy something', 'run a command on a real machine', or 'host a service', which can cause an agent to select this skill in many contexts where a remote paid VPS is unnecessary or risky. In this skill's context, over-broad routing is especially dangerous because invocation can lead to real-world resource provisioning, payments, and follow-on root operations on external infrastructure.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The markdown explicitly documents root command execution and server destruction but does not prominently warn that these actions are destructive, irreversible, and may incur cost or service loss. In this skill, the omission is more dangerous because the operations occur on real rented infrastructure, so an agent could execute privileged commands, reboot systems, or destroy servers without a strong confirmation boundary.

VirusTotal

50/50 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:91