Market Gap Analysis

Security checks across malware telemetry and agentic risk

Overview

The skills are mostly coherent developer and maintainer helpers, but one review helper defaults to running nested Codex with full-access sandbox bypass, so users should review it carefully before installing.

Install only if you trust the publisher and need ClawHub maintainer/development workflows. Before using autoreview, consider running it with --no-yolo or setting AUTOREVIEW_YOLO=0, and treat moderation, PR publishing, production migration, and external reviewer commands as actions that may change remote services or expose code diffs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal