Back to skill

Security audit

Stringclaw

Security checks across malware telemetry and agentic risk

Overview

This skill does what it says by enabling real phone calls, but it needs review because calls can be triggered too broadly without a clear final confirmation step.

Install only if you want an agent to place real phone calls through your Stringclaw account. Require the agent to confirm the action, destination/account, and possible charges before every call, and review the gateway and bridge setup before use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

High
Confidence
95% confidence
Finding
The skill advertises broad trigger phrases like 'call me', 'give me a call', and 'phone me' for an action that initiates a real outbound phone call. Because this is a high-consequence action with cost, privacy, and interruption implications, overly broad activation language increases the risk of accidental invocation without sufficiently explicit user consent.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The description says the skill makes real phone calls, but it does not present a prominent upfront warning about the real-world effect, potential charges, and privacy implications before use. For a skill that triggers telephony, lack of a strong warning can mislead users or downstream agents and contributes to accidental or insufficiently informed execution.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.