ClawBack
Security checks across malware telemetry and agentic risk
Overview
The skill's instructions, optional env vars, and file access are coherent with a local CLI-based group expense tracker; nothing requested is disproportionate to its stated purpose.
This skill appears internally consistent with a local CLI-based expense tracker, but before installing or using it consider: 1) Ensure you trust the 'clawback' package source (refs suggest a GitHub repo); install it in a controlled environment or inspect the package if uncertain. 2) The skill will read/write local files under ~/.clawback — back these up if you care about your data. 3) Google Sheets integration requires the 'gog' CLI and storing a GOG_KEYRING_PASSWORD in your shell/profile; avoid putting secrets in plaintext profiles if that concerns you and prefer OS keyrings where possible. 4) Developer-only tests reference ANTHROPIC_API_KEY — these are not needed for normal operation but would enable LLM calls if you run them. 5) The agent will execute the local 'clawback' binary; make sure that binary is the intended software (verify pip/package/GitHub source) before allowing the skill to run it.
SkillSpector
SkillSpector findings are pending for this release.
VirusTotal
No VirusTotal findings
