Article Summary Card

Security checks across malware telemetry and agentic risk

Overview

The skill mostly matches its article-summary purpose, but its optional installer can delete an existing destination folder without confirmation.

Install only if you are comfortable with local helpers fetching URLs or reading files you provide and saving derived output files. Do not run the OpenClaw install helper with a custom --dest unless you have verified the path, because an existing directory there will be deleted first.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The prompt hard-codes the assistant role and output language to Chinese without any user choice or fallback. This can override user preference or downstream system expectations, causing misuse, degraded accessibility, or policy conflicts in multilingual environments, though it does not by itself enable direct code execution or data exfiltration.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The installer unconditionally removes the destination directory if it already exists, with no prompt, backup, or validation that the path is safe to delete. Because the destination is user-controllable via --dest, a mistaken or unexpected path can cause destructive data loss in the user's filesystem, especially if the script is run with elevated privileges.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal