Back to skill

Security audit

Clawbridge Skill

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed recurring web-scouting assistant that finds professional contacts and drafts briefs for human review, with no executable code or hidden behavior found.

Install this only if you want recurring public web and community scouting for professional contacts. Configure strict search and fetch limits, keep avoid lists current, deliver briefs only to trusted internal channels, review every match and draft manually, and avoid collecting or using sensitive personal information.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Intent-Code Divergence

Medium
Confidence
88% confidence
Finding
The skill states it must never auto-send outreach in MVP, yet its configuration explicitly supports external delivery targets such as email, Slack, and Discord. This creates a policy/behavior mismatch that could enable automated outbound transmission of scouting results or draft outreach without sufficient human review, increasing the risk of unwanted contact, spam, or privacy violations.

Missing User Warnings

Medium
Confidence
81% confidence
Finding
The overview describes nightly scouting across Moltbook, communities, and the open web, but does not clearly warn users that the skill performs recurring external data collection. This lack of transparency can cause users to enable continuous monitoring without understanding the privacy, compliance, or reputational implications of collecting third-party profile and activity data.

Missing User Warnings

Medium
Confidence
79% confidence
Finding
The skill says it produces personalized outreach drafts but does not clearly disclose that those drafts may be generated from discovered candidates' personal or profile information. Without that warning, users may not appreciate that the system is processing third-party personal data for message generation, which raises privacy, consent, and misuse concerns.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.