Security audit
EigenSkill Builder
Security checks across malware telemetry and agentic risk
Overview
This skill is a documentation-only guide for creating and publishing ClawHub skills, with its potentially account-changing commands shown as explicit user-run workflow examples.
This looks safe to install as an instructional skill. Before following its publishing or update workflow, review generated skill files yourself and intentionally approve any `clawhub publish`, `clawhub update`, or `clawhub install` command because those actions can publish content under your account or change local installed skills.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
