ListenClaw

Security checks across malware telemetry and agentic risk

Overview

ListenClaw is a narrow voice-formatting skill; its main caveat is that the optional installer fetches the skill file from a mutable GitHub branch.

This appears appropriate to install if you want voice-friendly responses. If using install.sh, inspect the GitHub source first or prefer installing the reviewed artifact directly, because the script pulls the latest SKILL.md from the repository's main branch.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
70% confidence
Finding
The script modifies the user's agent workspace by downloading and writing a remote file without any prior user-facing notice or confirmation. This reduces informed consent and makes silent workspace modification easier, which increases the risk of unexpected or malicious skill content being installed through a trusted-looking installer.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal