data-cleaning-claw

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed local data-cleaning skill that reads user-provided data and writes cleaned output files without evidence of hidden access, exfiltration, persistence, or destructive behavior.

Install only if you are comfortable letting the skill process the files or pasted data you provide and write cleaned outputs plus a JSON report in the workspace. Keep backups of important originals, choose output paths carefully to avoid overwriting files, and review sensitive or regulated datasets before using a local cleaning workflow.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding
The skill writes uploaded or pasted user data to the workspace and generates cleaned output/report files, yet it declares no permissions. This creates a mismatch between documented behavior and the platform's security model, which can bypass review expectations and make file-writing side effects less visible to operators or users.

Vague Triggers

Medium
Confidence
74% confidence
Finding
The trigger phrases are broad and common for normal data-related conversations, including generic terms like data cleaning, deduplication, and preprocessing. That increases the chance of unintended invocation, which in this skill can lead to automatic file processing and workspace writes on content the user may not have intended to hand over to an external cleaning workflow.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal