Back to skill

Security audit

agclaw

Security checks across malware telemetry and agentic risk

Overview

This skill coherently calls the AppGrowing/YouCloud API for advertising-material analysis, with no evidence of hidden execution, persistence, destructive behavior, or exfiltration beyond the stated service call.

Install only if you intend to send your advertising-analysis prompts to AppGrowing/YouCloud and have the required account access. Prefer configuring YOUCLOUD_API_KEY as an environment variable rather than pasting it into chat, and avoid submitting confidential campaign or business data unless that matches your organization's data-sharing policy.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

High
Confidence
98% confidence
Finding
The skill explicitly instructs the agent to accept API keys pasted directly into chat and use them for outbound requests, but provides no safeguards for secret handling, redaction, retention, or user warning. This creates a real credential-exposure risk because users may disclose long-lived secrets in conversation transcripts, logs, or downstream tooling, and the skill normalizes unsafe secret-sharing behavior.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill sends user input and session identifiers to a third-party API, but the disclosure is incomplete and not presented as a meaningful data-transfer warning or consent gate. This is dangerous because users may unknowingly share sensitive business queries, internal campaign data, or identifiers with an external processor, increasing privacy, confidentiality, and compliance risk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.