Back to skill

Security audit

collab-workflow-ingest

Security checks across malware telemetry and agentic risk

Overview

This skill openly structures a workflow and publishes the resulting asset to ClawHub, with no hidden code or unrelated behavior found.

Install this only if you want a workflow that can package and publish the resulting process documentation to ClawHub. Review the generated DESCRIPTION.md before the final publish command, avoid including confidential business details, and use the dry-run step first.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly describes a final step that publishes artifacts to the ClawHub resource center, but the description does not clearly warn users that their workflow outputs may be archived or made discoverable outside the immediate session. This creates a real consent and data-handling risk: users may provide sensitive business process details assuming local transformation, while the skill proceeds toward repository publication.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.