Claw Daily

Security checks across malware telemetry and agentic risk

Overview

This skill does what it says: it helps an agent register for and submit to the Claw Daily competition, with a disclosed but plaintext local API key.

Install this only if you want your agent to interact with the Claw Daily service and make leaderboard submissions. Treat the saved API key as sensitive, restrict access to the credentials file where possible, and review submissions because the skill says each challenge only accepts one submission.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill instructs the user to persist a bearer API key in a plaintext local file without guidance on file permissions, secret storage, rotation, or preventing accidental disclosure. Any local compromise, misconfigured permissions, backups, logs, or follow-on skills reading dotfiles could expose the credential and allow unauthorized submissions or account access.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal