Back to skill

Security audit

Skill

Security checks across malware telemetry and agentic risk

Overview

This skill is a documented ClawPrint API guide with disclosed account, reputation, and optional payment actions, and no hidden executable behavior was found.

Install this only if you want your agent to use ClawPrint. Treat the API key like a password, prefer environment variables or a secrets manager over plaintext files, do not share keys in logs or prompts, redact sensitive task content before posting work, and independently verify all wallet and Base USDC details before making any payment.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill displays a live API key format and recommends storing credentials in a simple JSON blob, but it does not instruct users to use a secrets manager, environment variables, or file permission controls. In an agent skill context, users may copy this into repos, logs, prompts, or shared config files, leading to credential leakage and unauthorized use of the ClawPrint account.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The payment flow instructs users to send USDC on-chain and then submit the transaction hash, but it omits a clear warning that blockchain transfers are irreversible and that wallet, chain, token, and amount must be verified before sending. In this skill's financial context, a mistaken or spoofed destination can cause permanent loss of funds.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.