Back to skill

Security audit

Deep Research Pro

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed web-research helper that searches public sources and saves cited reports locally, with no evidence of hidden or destructive behavior.

Install this only if you are comfortable with your agent making outbound web requests and saving research reports locally. Avoid using sensitive internal topics or secrets in research prompts, and ask the agent to keep results in chat if you do not want files written under ~/clawd/research.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Confidence
83% confidence
Finding
The README promotes web fetching, deep reads, and saving output to local files without warning users that queries may be sent to third-party search/content providers and that generated reports may persist sensitive information on disk. In an agent setting, this can lead to unintentional disclosure of private prompts, internal topics, or sensitive research results, especially if users assume the skill is purely local or harmless.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill is written to activate on essentially any user request for 'research on any topic,' making its trigger scope extremely broad. This can cause the agent to invoke a powerful multi-step workflow, including web fetching and file writes, in situations where the user may have intended a simpler answer or where a narrower, safer skill should have been selected instead.

VirusTotal

54/54 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.