Back to skill

Security audit

Clawhub Skill

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate Citedy marketing integration, but it can publish publicly, spend credits, and run recurring automation without consistently requiring explicit confirmation.

Install only if you trust Citedy with your connected marketing, social, search, and content accounts. Before using it, require the agent to confirm destinations, visibility, schedule, and credit impact before publishing, creating sessions, deleting content, changing settings or webhooks, rotating keys, or running expensive generation; keep spend and cadence limits in the Citedy dashboard and know how to pause sessions and revoke the API key.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Context-Inappropriate Capability

Medium
Confidence
96% confidence
Finding
The skill explicitly instructs the agent to make periodic keep-alive calls every 4 hours even when not tied to an active user request. That creates agent-initiated background network activity and ongoing use of stored credentials outside the user's immediate intent, which can violate least-privilege and surprise users with hidden external communication.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The overview and usage guidance promote auto-publishing to connected social accounts and cron-based recurring sessions without requiring an explicit confirmation step before creating external side effects. In a skill that can post publicly and consume credits, this raises the risk of unintended publication, reputational damage, and surprise billing.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The primary workflow chains article generation and social adaptation in a way that can result in publication by default, yet it does not prominently require the user to confirm live posting first. Because connected accounts may publish automatically, a user asking for content generation could unintentionally trigger real-world posting to public channels.

Missing User Warnings

Medium
Confidence
98% confidence
Finding
The article generation API defaults to immediate publishing based on tenant settings or a true fallback, which means a content-generation request can create a public post unless the caller opts out. Default-on publication is especially risky in a marketing skill because the likely user intent is often drafting or review, not unconditional public release.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The social adaptation endpoint notes that adaptations may be auto-published to connected accounts, but the skill does not require a prominent confirmation checkpoint before invoking it. This can turn a formatting/adaptation action into immediate public posting across social channels, creating reputational and operational risk disproportionate to the user's likely expectation.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The recurring session endpoint auto-starts a cron-based content generation workflow and may lead to ongoing automated publishing and repeated credit consumption, yet the skill lacks a strong warning and explicit approval requirement. Persistent automation materially increases risk because a single misunderstood instruction can produce repeated external actions and ongoing charges.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.