Oraclaw Simulate

Security checks across malware telemetry and agentic risk

Overview

This is a small instruction-only Monte Carlo simulation skill with a disclosed API key requirement and paid usage, but no hidden code or persistence.

Install only if you intend to use OraClaw's paid simulation service. Use a dedicated API key where possible, monitor charges, and avoid submitting confidential financial, trading, or business formulas unless you are comfortable with OraClaw processing those inputs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The manifest declares a required environment variable `ORACLAW_API_KEY`, which indicates the skill depends on an external service, but the skill content does not clearly warn users that credentials will be used or that simulation inputs may be sent off-platform. This creates a real security and privacy risk because agents or users may invoke the skill without understanding the trust boundary, potentially exposing sensitive business, finance, or trading data to a third-party service.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal