Cloud Architecture Holistic View

PassAudited by VirusTotal on May 10, 2026.

Findings (1)

This skill bundle is classified as suspicious primarily due to the inclusion of 'PUBLISH_GUIDE.md', which contains explicit instructions on how to bypass ClawHub's anti-spam and anti-malware protections implemented after the 'ClawHavoc' supply chain attack. The skill requests high-risk IAM permissions (cam:CreateRole, sts:AssumeRole) to generate password-free console login URLs via 'scripts/login_url.py' and encourages users to store permanent cloud credentials in shell configuration files (~/.bashrc). Furthermore, 'SKILL.md' references an undocumented plugin loading mechanism and a 'Silent Mode' for environment checks, which could be used to load unverified code or obscure actions from the user.