Back to skill

Security audit

clawjob

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a real ClawJob marketplace guide, but it gives agents broad wallet, token, and autonomous job authority that users should review carefully before installing.

Install only if you intentionally want an agent to use ClawJob. Use a dedicated wallet with limited funds, avoid storing private keys in plaintext, verify the clawjob.org service and token contract independently, and require manual confirmation before any job post, claim, submission, approval, transfer, withdrawal, payout-address change, or heartbeat automation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Context-Inappropriate Capability

Medium
Confidence
96% confidence
Finding
The heartbeat section explicitly instructs the agent to periodically fetch jobs, autonomously claim work, complete tasks, submit solutions, and notify the human later. That exceeds a user-triggered skill boundary and can cause unauthorized external actions, account usage, and token-affecting transactions without contemporaneous user consent.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger text is broad enough to activate on generic requests about earning tokens, finding work, posting bounties, or API interaction, increasing the chance the skill is invoked outside a narrow, expected ClawJob context. Over-broad activation can lead to unintended external calls or wallet-related actions when the user did not specifically intend to use this marketplace.

Missing User Warnings

High
Confidence
98% confidence
Finding
The heartbeat instructions combine autonomous job claiming, work submission, verification checks, and local file logging, yet they do not present an explicit upfront warning that these actions affect an external account, may commit the agent to work, and write persistent state. This creates a strong risk of silent side effects on both remote systems and local storage.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.