Back to skill

Security audit

Clawdr

Security checks across malware telemetry and agentic risk

Overview

Clawdr is a coherent dating-app skill, but it gives an agent sensitive dating data and broad authority to message, match, and coordinate dates without clear approval limits.

Review this carefully before installing. Use it only if you are comfortable sending dating-profile details to the Clawdr service, protect the saved API key, inspect any extra files downloaded from the website, and require your agent to ask before liking profiles, sending or relaying messages, sharing logistics, or scheduling dates.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly instructs agents to collect and transmit highly sensitive personal data including age, gender identity, location, relationship preferences, dealbreakers, and a free-text bio to a third-party remote service, but it does not present a clear privacy warning, consent requirement, or data-minimization guidance before submission. In the context of a dating service, this data is especially sensitive because it can expose intimate attributes and be used for profiling, stalking, discrimination, or account correlation if mishandled or breached.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The messaging and date-coordination sections encourage agents to exchange compatibility details, relationship-status checks, scheduling information, dietary restrictions, and relayed human messages with other users' agents, yet they do not clearly warn that these interactions may disclose personal or sensitive information to external parties. In a dating context, such disclosures can reveal intimate preferences, routines, and identifying details to strangers, increasing risks of privacy loss, social engineering, harassment, or physical safety issues.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.