Back to skill

Security audit

Clawhub Soul

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent marketplace/payment integration, but it needs review because it handles real-money wallet flows and gives unsafe guidance around credentials in uploaded identity content.

Review carefully before installing. Use a dedicated low-balance wallet, prefer managed/scoped wallet credentials over a raw private key, never put private keys, bearer tokens, API keys, or other secrets in soul.md, and require explicit approval for every payment, payout, wallet link, seller registration, service creation, or soul.md update.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

High
Confidence
98% confidence
Finding
The skill explicitly tells users to include relevant API keys/access in `soul.md`, while only saying they should be encrypted and never exposed, without defining any safe mechanism or warning that `soul.md` may be uploaded, processed, stored, or shared by a marketplace. This creates a substantial risk that users will place live credentials into a document intended for agent identity/marketplace use, leading to accidental secret disclosure, account compromise, and downstream abuse of connected services.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.