Back to skill

Security audit

ClawVoyant

Security checks across malware telemetry and agentic risk

Overview

This skill does what it claims: searches for YouTube videos through DuckDuckGo and retrieves transcripts through a YouTube transcript library, with no evidence of hidden collection, credential access, or destructive behavior.

Install only if you are comfortable with your YouTube search terms and requested video IDs being sent to DuckDuckGo and YouTube transcript-related services. Avoid using it for confidential research topics unless that disclosure is acceptable.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Low
Confidence
90% confidence
Finding
The transcript tool sends a user-supplied YouTube video identifier to an external third-party service to retrieve transcript data, but the tool description and interface do not disclose that this network transfer will occur. This is a real privacy/transparency issue because users may reasonably assume local-only processing and unknowingly expose viewing interests or sensitive research topics to external services.

Missing User Warnings

Low
Confidence
95% confidence
Finding
The search function forwards arbitrary user queries to DuckDuckGo without any explicit disclosure that the query leaves the local environment and is processed by an external provider. This creates a genuine privacy concern because user prompts may contain sensitive interests, internal project names, or confidential research terms that are unnecessarily shared with a third party.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.