FAQ Support

Security checks across malware telemetry and agentic risk

Overview

This is a low-risk, instruction-only workflow for turning support conversations into PDP FAQ copy, with the main caution being to sanitize customer tickets before sharing them.

This skill appears safe to use as an instruction-only drafting aid. Before using it with real support tickets or chat logs, remove customer PII, avoid sharing unnecessary full transcripts, and verify any product, warranty, safety, or compliance claims before publishing PDP copy.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Risk analysis

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

#
ASI06: Memory and Context Poisoning
Low
What this means

If raw support logs are pasted into the agent, customer names, emails, addresses, or sensitive business details could be exposed in the working context or copied into drafts.

Why it was flagged

The skill expects recent customer-support conversations to be used as input. That is purpose-aligned and it explicitly mentions PII handling, but raw tickets or chats may contain customer personal data or untrusted customer text.

Skill content
Ingestion sketch — what "last 30 days" means (channels, languages, product scope), deduping, and PII handling at a high level.
Recommendation

De-identify exports before use, remove names/emails/addresses, provide counts or paraphrased examples where possible, and treat customer transcript text as data rather than instructions.