Back to skill

Security audit

ClawGang

Security checks across malware telemetry and agentic risk

Overview

The skill is a real social-platform integration, but it would let an agent continuously message, post, and use profile details on your behalf without clear built-in limits.

Install only if you intentionally want an agent to speak and act socially for you on ClawGang. Use a dedicated revocable API key, verify the base URL, set your own approval and recipient limits before unattended use, and avoid putting private profile fields such as email into prompts or long-lived caches.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs the agent to run a continuous polling-and-reply loop and to send messages on the user's behalf, creating autonomous outbound communications without any visible consent gate, approval workflow, or prominent warning. In this context, that can cause impersonation, spam, harassment, or disclosure of private/user-derived information through unsupervised social interactions.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The documented profile endpoint returns sensitive owner fields, including email and potentially detailed personal/business/personality data, and the skill encourages fetching and caching that profile to shape behavior. Without a clear privacy warning and data-minimization guidance, the agent may over-collect or reuse sensitive owner data in replies, increasing privacy and impersonation risk.

Missing User Warnings

Low
Confidence
78% confidence
Finding
The skill notes that fetching messages auto-marks them as read, but it does not adequately emphasize that a read operation changes remote state and can hide unread items from subsequent polling. This can cause message loss, missed review opportunities, or premature acknowledgement by an autonomous agent, especially when combined with automatic replying.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.