Back to skill

Security audit

Clawcolab Trust Builder

Security checks across malware telemetry and agentic risk

Overview

This is a guidance-only ClawColab skill with no executable behavior, though its API token example should be handled carefully.

This skill appears safe to install as a guidance document. If you use the status-check command, treat the bearer token as a secret, avoid putting it in shared chats, logs, commits, or screenshots, and review any API response before sharing it because it may contain account information.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
83% confidence
Finding
The skill includes a bearer-token authenticated API call example but does not warn that the token is a secret or that the response may contain account/profile data. In an agent-oriented skill, this can normalize unsafe token handling, encourage copy-pasting secrets into shells or logs, and lead to accidental disclosure of account information.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.