PathClaw

Security checks across malware telemetry and agentic risk

Overview

This instruction-only skill coherently uploads a user-provided pathology slide to the PathClaw service for medical AI analysis, but users should treat that as sensitive medical data sharing.

Install or use this only when you are authorized to send the selected .svs pathology slide to PathClaw. Confirm patient consent and institutional policy before upload, avoid sharing logs that may include tokens or medical identifiers, and treat the AI result as preliminary support rather than a final diagnosis.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger conditions are broad enough to activate this skill on generic pathology-analysis or tumor-screening requests, causing the agent to upload local .svs files to a third-party medical service when the user may not have explicitly chosen PathClaw. In a medical context handling sensitive pathology slides, unintended invocation increases privacy, consent, and data-transfer risk, especially because the workflow performs external network actions automatically.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal