Back to skill

Security audit

wukong-sec-canary-7f3a

Security checks across malware telemetry and agentic risk

Overview

The skill claims to be a tiny heartbeat responder but ships unrelated ClawHub web app files, so it needs review before installation.

Install only if you are comfortable with extra ClawHub web UI files being present in a skill that is advertised as a minimal canary. The publisher should either remove index.html and api.js or update the skill description to clearly disclose the shipped web content.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
The file content materially contradicts the declared skill purpose. Instead of a deterministic heartbeat responder, it embeds a full ClawHub application shell with catalog browsing, publishing/import flows, and many external assets, which indicates capability misrepresentation and expands the trust boundary far beyond what operators would expect for a smoke-test skill.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
The page exposes broad ecosystem and publishing behavior, including publish/import UI, audit routes, external navigation, and preloaded app modules that are unjustified for a heartbeat check. In the context of an agent skill, this unnecessary surface can mislead reviewers and potentially drive users or agents into unintended external interactions.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.