Back to skill

Security audit

ClawTrace Runtime Observatory

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed debug observer, but it asks for broad access to full runtime context and internal workflow traces without clear redaction or authorization limits.

Treat this as a Review item rather than malware. Install only in environments where users and operators are comfortable exposing full workflow traces and prior outputs. Avoid using it around secrets, credentials, private prompts, personal data, or sensitive business workflows unless the host runtime adds explicit consent, redaction, retention limits, and a safer summary-only mode.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill can be activated by generic terms like "debug" and "trace," which are common in normal user conversations. That creates an overly broad trigger surface where the observability skill may run unintentionally and expose internal workflow data, logs, or prior outputs when the user did not explicitly request sensitive diagnostics.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The user-trigger conditions are underspecified because phrases like "查看workflow" and "查看运行过程" lack scope, exclusions, and authorization rules. In practice, ordinary requests about process visibility could invoke the skill and cause disclosure of internal system structure, nested skills, or sensitive trace artifacts.

Ssd 3

Medium
Confidence
97% confidence
Finding
The skill explicitly requires reading and retaining complete runtime context, including `context.trace_logs`, `context.previous_output`, and the full `context.data_envelope`. In a debugging skill, that creates a strong natural-language data exposure path because secrets, private prompts, intermediate outputs, or other sensitive context may be surfaced to users or logged unnecessarily.

Ssd 3

High
Confidence
98% confidence
Finding
The reconstruction and final-goal sections direct the skill to reveal how the AI "thinks," self-critiques, generates roles, arbitrates conflicts, and performs runtime scheduling. Exposing internal reasoning and self-critique details materially increases the risk of prompt leakage, policy disclosure, attack adaptation, and extraction of sensitive internal decision processes.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.