Back to skill

Security audit

Allow your claws to do things remotely on a Desktop machine via MCP

Security checks across malware telemetry and agentic risk

Overview

This skill is a clearly described remote-control integration, but users should treat it as powerful because it can run commands, control a browser, and read or change files on the remote host.

Install this only for a remote machine you intend the agent to control. Configure the Remote Claws server with a strong bearer token, narrow IP and host allowlists, and per-action permissions; avoid enabling file deletion, broad file writes, command execution, or authenticated browser access unless you need them for the task.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
96% confidence
Finding
This skill advertises full remote control of a machine, including command execution, browser automation, and file read/write, but does not prominently warn about destructive actions, sensitive data exposure, or privacy impact. In practice, an agent using this skill could delete files, exfiltrate data, execute malware-like actions, or interact with authenticated browser sessions on the remote host without the user appreciating the risk.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.