Writing Claw

Security checks across malware telemetry and agentic risk

Overview

This is a text-only creative writing helper with broad fiction-writing triggers but no code, credentials, network access, or hidden persistence.

Reasonable to install for creative writing and story planning. Be aware it may activate for many fiction-related requests, so avoid sharing private drafts or personal material unless you are comfortable putting that content into the agent conversation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill advertises an extremely broad trigger scope for nearly any fiction-related request, which can cause it to activate when a narrower or safer skill would be more appropriate. Over-broad routing increases the chance of misclassification, prompt collision, and unintended handling of user inputs at large scope, especially in systems where skill selection affects behavior or data exposure.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal