Back to skill

Security audit

Blackjack Helper

Security checks across malware telemetry and agentic risk

Overview

The bundle is coherent for ClawHub maintenance, but it merits Review because its autoreview helper defaults to full-access sandbox bypass and can fall back to external reviewer CLIs.

Install only if you are comfortable with ClawHub maintainer workflows that can use authenticated GitHub, Convex, and ClawHub CLI actions. Treat the autoreview helper carefully: prefer --no-yolo or AUTOREVIEW_YOLO=0 for ordinary review, and disable automatic fallback reviewers when private code or secrets may appear in diffs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.