Back to skill

Security audit

Oraclaw Bandit

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only A/B optimization skill whose external API use is expected for its purpose, with no hidden code or destructive behavior found.

Before installing, verify the separate OraClaw MCP server you configure, use an API key with appropriate limits, monitor paid usage, and avoid sending sensitive personal, regulated, or proprietary context unless you have confirmed OraClaw's data handling and compliance terms.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill requires an API key and directs the user to connect to an external MCP server, which strongly implies that supplied arms, rewards, and contextual/history data may be transmitted to a third-party service. The documentation does not clearly disclose this data flow, retention, or privacy implications, creating a meaningful risk of unintended external sharing of potentially sensitive experimentation or user-behavior data.

VirusTotal

42/42 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.