Language Tutor

Security checks across malware telemetry and agentic risk

Overview

The artifact appears to be a coherent set of developer and ClawHub operations helper skills; it uses powerful tools, but the sensitive actions are disclosed and mostly gated by user direction.

Install only if you intend to use these skills for ClawHub/Convex development or staff operations. Use the moderation and PR workflows with the correct authenticated account, review commands before writes, and consider the autoreview helper's --no-yolo option if you do not want nested Codex review to run with full filesystem/network access.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal