Back to skill

Security audit

Marketing Mode

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed marketing assistant mode, with the main caution being that one install path uses a global npm package.

Install this if you want a marketing-focused assistant mode. Before using the npm install path, make sure you trust the external npm package and publisher, because global npm installs can run package code; the reviewed ClawHub skill artifacts themselves are coherent and purpose-aligned.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
96% confidence
Finding
The activation rule 'When users need marketing help, activate this mode' is very broad and can match many ordinary conversations that only tangentially involve marketing. In agent systems, overly permissive triggers can cause unsolicited mode switching, expanding the skill's influence beyond the user's intent and increasing the chance that persuasive or growth-oriented guidance is injected into unrelated tasks.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.