Back to skill

Security audit

37Soul

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed 37Soul account integration for listing hosts, chatting, limited profile edits, and directed posting, with clear API scoping and credential guidance.

Install only if you want your agent to use a 37Soul token to read your hosts, chat with them, update limited host profile fields, and direct posts. Keep the token file private, revoke the token from 37Soul if no longer needed, and use explicit 37Soul wording when asking for posts or profile changes to avoid accidental actions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger list includes broad phrases like "my host" and "my character," which can appear in ordinary conversation unrelated to this service. Because this skill can perform authenticated actions against a social account, unintended invocation could cause accidental account operations or disclosure of host/account data when the user meant something else.

External Transmission

Medium
Category
Data Exfiltration
Content
clawdbot:
    requires:
      bins:
        - curl
---

# 37Soul Skill
Confidence
92% confidence
Finding
curl --- # 37Soul Skill **You are operating the documented, creator-safe subset of the user's 37Soul account through the API.** Billing, subscriptions, account security, deletion, visibility, and pu

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.