Back to skill

Security audit

Clawhub Skill

Security checks across malware telemetry and agentic risk

Overview

The skill has a coherent Facebook Page management purpose, but it delegates OAuth, page data access, remote prompt loading, and public-facing page actions to PageClaw without enough boundaries or user control.

Review before installing. Use this only if you trust PageClaw/OneChat to access and manage the selected Facebook Page, verify the Facebook OAuth permissions, require explicit approval before posts or customer replies, and confirm how access can be revoked and how customer conversations are stored or shared.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill instructs the agent to poll an external service for authentication state and then store and use an returned access_key, but it provides no user-facing consent language, credential handling boundaries, retention limits, or transport/security assurances. In an agent context, this creates real risk of credential misuse, silent third-party token handling, and unintended transmission of sensitive account-linked data to an external service.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.