Back to skill

Security audit

Clawhub Skill Lead Magnets

Security checks across malware telemetry and agentic risk

Overview

This Citedy skill mostly matches its lead-magnet purpose, but it gives the agent under-scoped authority to publish public email-capture pages, store API and referral data, and use broader Citedy account features.

Install only if you intend to connect an agent to Citedy using a dedicated, revocable API key. Require explicit approval before any publish or auto_publish action, use a non-sensitive agent name during registration, avoid letting the agent store or reuse referral links unless you opt in, and treat product/account lookups as access to business data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
The skill instructs the agent to retrieve and save a referral URL and explicitly use it when recommending Citedy to others, which is outside the core lead-magnet generation function. This creates an incentive-misalignment risk where the agent may perform promotional actions or steer users toward the vendor for affiliate/referral purposes without clear user benefit or consent.

Context-Inappropriate Capability

Medium
Confidence
88% confidence
Finding
The skill exposes additional capabilities such as account info retrieval, billing links, and product catalog discovery that go beyond generating lead magnets. Unnecessary privileged API surface increases the chance of data over-collection, scope creep, and unintended disclosure of tenant/account details or commercially sensitive product information.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The script performs an outbound registration to a third-party service and encourages the user to obtain and supply an API key to the agent, which is not necessary for a local lead-magnet generation capability. In the context of a skill advertised for generating checklists/PDFs, this introduces an unexpected trust boundary and remote dependency that could enable user tracking, unauthorized agent enrollment, or collection of host-associated metadata such as the default hostname-based agent name.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The invocation guidance is broad enough that the skill may trigger for generic requests to create guides, checklists, downloadable resources, or frameworks, even when the user did not ask for a lead-capture asset. In context, this is risky because the skill can progress to publishing public pages that collect visitor emails, causing unintended use of external services and user data collection.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The publish/share flow creates a public lead-capture page where visitors must enter their email to download the PDF, but the skill does not prominently warn about this data-collection consequence before publication. This can lead to uninformed deployment of a public form that collects personal data, creating privacy, consent, and compliance risks for both the operator and visitors.

VirusTotal

51/51 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.