Java Spring Boot

Security checks across malware telemetry and agentic risk

Overview

This is a coherent Spring Boot development guide with standard local coding tools enabled, and the artifacts show no hidden data access, persistence, or exfiltration.

This skill appears safe for its stated purpose. Before installing, note that it can use standard development capabilities to read, edit, and run commands in your project, so review changes and commands as you would with any coding assistant.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Risk analysis

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

#
ASI02: Tool Misuse and Exploitation
Low
What this means

The agent may inspect and change project files or run development commands while helping with Spring Boot work.

Why it was flagged

The skill permits file access, file modification, code search, and shell commands. This is expected for a Spring Boot coding assistant, but it can affect the user's local project if invoked.

Skill content
allowed-tools: Read, Write, Bash, Glob, Grep
Recommendation

Use it in intended project directories, review proposed file changes, and approve shell commands only when they match your requested task.

#
ASI04: Agentic Supply Chain Vulnerabilities
Info
What this means

You have less information about where the skill came from or how to audit its upstream history.

Why it was flagged

The registry metadata does not provide an upstream source or homepage, so provenance is harder to independently verify. The supplied artifacts themselves do not show suspicious install behavior.

Skill content
Source: unknown; Homepage: none
Recommendation

Install only if you trust the registry entry or owner, and keep reviewing the included files when versions change.