Security audit
Generate Fractional CFO Firm Client Education Handout
Security checks across malware telemetry and agentic risk
Overview
The artifacts are mostly coherent for ClawHub maintenance, but they grant high-impact moderation/GitHub authority and include a review helper that runs nested agents with full filesystem access by default.
Install or use this only if you are a ClawHub maintainer and understand the staff-level effects. Prefer dry runs, require explicit confirmation for writes, use least-privilege ClawHub/GitHub tokens, and run autoreview with its no-yolo option or equivalent sandboxing when possible.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
