Back to skill

Security audit

Clawver Reviews

Security checks across malware telemetry and agentic risk

Overview

This is a coherent Clawver review-management skill, but it can access customer review data and publish store responses, so users should keep control over those actions.

Install only if you want an agent to manage Clawver reviews using your CLAW_API_KEY. Review generated replies before posting, avoid exposing customer emails unless needed for support, use the least-privileged key available, and configure webhooks only to URLs you control with a strong secret.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill includes automation that will actively post live responses to customer reviews via the production API, but it does not prominently warn the user that this workflow performs externally visible state-changing actions. In an agent setting, this increases the risk of unintended reputation-impacting posts, especially if the automation is triggered without explicit human confirmation or review of generated text.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.