Back to skill

Security audit

ClawSkill

Security checks across malware telemetry and agentic risk

Overview

This is disclosed token-mining software, but it relies on an external miner package and sends recurring hardware fingerprints, with some scope gaps users should review carefully.

Install only if you intentionally want token-mining software on this machine. Review the exact PyPI or npm package and linked source before running it, avoid global install and service mode until trusted, expect repeated hardware attestation data to be sent to RustChain, and monitor CPU, power, and network usage.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Intent-Code Divergence

Medium
Confidence
93% confidence
Finding
The documentation presents 'no external downloads at install time' as a security assurance, while the actual installation path requires fetching the package from PyPI or npm first. This is materially misleading because users may infer a stronger supply-chain guarantee than actually exists, reducing scrutiny of the package source and installer trust boundary.

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The skill claims only a narrow set of hardware attributes are transmitted, but later describes a broader fingerprinting and anti-emulation mechanism involving multiple microarchitectural and behavioral signals. In a mining/attestation context, this inconsistency is dangerous because it can conceal the true scope of device fingerprinting and undermine informed user consent for privacy-sensitive telemetry.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.