Back to skill

Security audit

Find Skills for ClawHub

Security checks across malware telemetry and agentic risk

Overview

This is mostly a ClawHub skill-search helper, but it also includes broader install, update, publish, sync, and memory-history guidance that users should review before trusting it.

Install only if you want an assistant to search ClawHub and potentially help manage skills. Approve each install, update, publish, or sync command explicitly, and avoid using publish or sync unless you have reviewed exactly which local files would be uploaded.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (9)

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The development guide materially expands a discovery skill into installation, update, and other operational workflows that exceed the stated purpose of finding available skills. This increases the chance the agent will perform side-effecting actions a user did not request, especially because install/update actions can modify the environment and fetch untrusted packages.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
Adding login, publish, and sync workflows to a skill meant for finding skills creates unjustified registry-management capabilities with account and supply-chain implications. If followed by an agent, these actions could authenticate to external services, publish artifacts, or alter registry state far beyond user intent.

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The guide recommends persisting search history and installation tracking in memory even though such storage is unnecessary for basic skill discovery. This creates avoidable privacy and data-retention risk by recording user interests and behavior without clear consent, minimization, or retention controls.

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The document presents itself as a search skill while embedding broader instructions for installation, updates, and publishing, creating a mismatch between declared purpose and effective behavior. This kind of scope drift is dangerous because it can mislead reviewers and users about what actions the skill may induce an agent to take.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The skill is scoped as a discovery helper, but it also directs the assistant to perform state-changing actions such as installing skills and operational actions like updating, publishing, and syncing. This expands the effective privilege and behavior surface beyond the declared purpose, increasing the chance that a user or downstream agent triggers package installation or data-publishing actions without sufficient scrutiny.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
Publishing and syncing local skills are materially different from searching a registry because they can exfiltrate local content or push private workspace assets to a remote service. In the context of a skill advertised for finding skills, these instructions are unjustified and could lead to unintended disclosure or supply-chain actions if the assistant follows them opportunistically.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The markdown explicitly suggests storing user search history in memory without any warning, consent flow, or privacy controls. Even if the data seems low sensitivity, it can reveal user projects, interests, and planned actions, making the collection unnecessary and privacy-invasive in this context.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation guidance includes broad phrases such as general OpenClaw help requests, which can cause the skill to trigger in unrelated conversations. Over-broad activation raises the chance that the agent will inject registry search, install, or other tool-oriented behavior where it was neither intended nor safe.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation criteria are broad enough to match generic questions about what OpenClaw can do, not just requests to search the registry. That can cause the assistant to invoke this skill in contexts where the user did not ask to search or install anything, which is especially risky because the skill also contains privileged, state-changing guidance.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.