Clawhub Search

Security checks across malware telemetry and agentic risk

Overview

This is a simple ClawHub marketplace search helper; it uses a ClawHub API token for API calls but does not include hidden code, persistence, or unrelated behavior.

Install only if you want an agent to search ClawHub Skills. Keep CLAWHUB_TOKEN in an environment variable or secret store, avoid pasting it into chat, and review any skill found by this helper before running the optional install command.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation conditions are broad enough to trigger on ordinary conversation about searching, skills, or ClawHub, which can cause the skill to activate unexpectedly. In an agent environment, overbroad triggering can lead to unintended external requests, unnecessary token use, and surprising behavior without clear user intent.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs use of a Bearer token with an external API but does not clearly warn that the user's credential will be transmitted to a third-party service. This creates a consent and secret-handling risk because users may not understand that invoking the skill sends their token off-platform and may expose account-scoped data or actions.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal