Back to skill

Security audit

Skills Search across ClawHub, skills.sh, and SkillsMP

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed search helper for finding other skills, with ordinary caution around sending search terms to external sites and reviewing install commands before use.

Safe to install as a search helper. Avoid sensitive or confidential search terms because queries can go to external services, and inspect any recommended third-party skill before running its install command, especially commands that skip confirmation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger description is extremely broad and instructs the agent to invoke this skill for many generic intents related to finding, recommending, or installing skills, including common Chinese phrases. This can cause unintended routing of user requests into a skill that executes external searches and shell commands, increasing the chance of over-collection, unnecessary network access, or surprising behavior.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.