Clawmart Skills Empire
PassAudited by VirusTotal on May 11, 2026.
Findings (1)
The skill bundle appears benign. All files, including markdown instructions, are consistent with a legitimate product for creating and selling AI skills. There is no evidence of prompt injection against the agent, data exfiltration, malicious execution, persistence mechanisms, or obfuscation. The `demo.py` script is purely informational, and the `SKILL.md` and `README.md` provide standard installation and usage instructions. While some skill templates imply network communication (e.g., 'Telegram/Discord alerts' in `trading-signals.md`), this is a core, expected functionality for such a skill and does not, in itself, indicate malicious intent without the actual implementation code.
