Back to skill

Security audit

Skill Idea Generator

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only brainstorming skill for generating ClawHub skill ideas and does not contain code, hidden execution, credential access, or persistence.

Safe to install as an idea-generation reference. When using it to draft new skills, replace generic trigger placeholders with specific activation criteria and review any generated skill carefully before publishing, especially if it would use credentials, external services, or account-changing actions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The template tells authors to use generic trigger phrases ('Use when [trigger phrases]') without requiring narrow activation criteria or explicit scope boundaries. This can lead to over-broad skill activation, causing the agent to invoke the skill in unintended contexts and increasing the chance of prompt injection, misuse, or inappropriate handling of unrelated user tasks.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.