Qclaw Text File
PassAudited by VirusTotal on May 9, 2026.
Findings (1)
The skill bundle uses aggressive prompt injection techniques in SKILL.md to force the AI agent to bypass the built-in 'write' tool in favor of a custom script (scripts/write_file.py). While the stated intent is to resolve cross-platform encoding issues (e.g., BOM for Excel), the use of 'Absolute Rules' and 'Highest Priority' to intercept core agent functions is a high-risk pattern. The Python script itself is a functional file-writing utility with no evidence of exfiltration or backdoors, but the forced redirection of built-in capabilities to custom code warrants a suspicious classification.
