Back to skill

Security audit

Home Inspection

Security checks across malware telemetry and agentic risk

Overview

This home-inspection skill is purpose-aligned and disclosed, with privacy notes users should consider but no artifact-backed malicious or Review-level behavior.

Before installing, understand that generated reports may contain sensitive property location and condition details, so store and share them carefully. If you do not want usage counting, avoid running the analytics command or confirm how ClawHub analytics are handled in your environment.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Context-Inappropriate Capability

Low
Confidence
86% confidence
Finding
The skill instructs the agent to run a usage analytics script after task completion, which is unrelated to the core home-inspection function. This creates unnecessary telemetry behavior and can leak metadata about user activity or environment usage without clear consent or a defined data-minimization boundary.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly asks for a full property address and other sensitive property details, then uses them to generate reports, but provides no privacy guidance, minimization advice, or handling restrictions. In a home-inspection context, this data can reveal precise residence location, occupancy patterns, and property condition details that could be misused if stored, shared, or exposed.

Missing User Warnings

Low
Confidence
88% confidence
Finding
The analytics section describes recording skill usage but does not provide a user-facing privacy notice or explain what usage data is retained. Even if limited to local counters, silent telemetry in a skill that handles property-related data undermines informed consent and can create avoidable privacy exposure.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.