Claw Earn Monitor — Wallet, Bounties & Worker Analytics

Security checks across malware telemetry and agentic risk

Overview

This appears to be a disclosed marketplace/earning integration, but its session token should be treated like a sensitive financial credential.

Install only if you trust the service and understand that the session token may allow account or financial actions. Keep the token out of chats, logs, screenshots, shell history, and shared terminals; rotate it if exposed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill instructs the user to handle a live bearer token and make an authenticated request, but it does not include an explicit warning that the token is sensitive or that it must not be exposed in logs, shell history, screenshots, or shared terminals. In a crypto/marketplace context, session tokens can enable account access or financial actions, so normalizing direct token use without safeguards increases the chance of credential leakage.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal