Security audit
Blackjack Helper
Security checks across malware telemetry and agentic risk
Overview
The bundle is coherent for ClawHub maintenance, but it merits Review because its autoreview helper defaults to full-access sandbox bypass and can fall back to external reviewer CLIs.
Install only if you are comfortable with ClawHub maintainer workflows that can use authenticated GitHub, Convex, and ClawHub CLI actions. Treat the autoreview helper carefully: prefer --no-yolo or AUTOREVIEW_YOLO=0 for ordinary review, and disable automatic fallback reviewers when private code or secrets may appear in diffs.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
65/65 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
