Back to skill

Security audit

RAMBOXIE Claw Rpg

Security checks across malware telemetry and agentic risk

Overview

The skill is an RPG add-on, but it asks for ongoing response hooks, background automation, and access to local memory/persona files while the referenced scripts are not present for review.

Install only if you are comfortable with an RPG skill reading local memory/persona files and writing persistent character state. Do not enable the after-reply AGENTS.md hook, cron setup, dashboard, or referenced Node commands unless the missing implementation files are available and reviewed, and keep response flavor text opt-in for environments where automatic message modification is acceptable.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The skill metadata and usage guidance encourage broad, recurring invocation across normal conversations, including post-reply hooks and automated jobs. That increases the chance the skill runs when unnecessary, causing unintended file reads/writes and behavior injection into user-facing responses without an explicit user request.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly states it reads SOUL.md and MEMORY.md to generate a character sheet, but it provides no warning, consent flow, or data-minimization guidance for potentially sensitive personal, behavioral, or system-level content in those files. In an agent environment, this can expose internal memory, prompts, or personal data to a feature that does not clearly need unrestricted access, increasing privacy and prompt-leakage risk.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.