Deep Research Gemini

Security checks across malware telemetry and agentic risk

Overview

This is a purpose-aligned Gemini research helper, with expected external API use and cost/privacy considerations rather than evidence of malicious behavior.

Install only if you are comfortable sending research prompts to Google Gemini and paying Gemini API costs. Use a dedicated API key with limits, do not include secrets or regulated/confidential data in queries unless approved, and inspect the referenced upstream script and requirements before executing them because they are not included in the ClawHub artifact.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly relies on a Gemini API key and sends user-provided research prompts to Google's external service, yet the description and usage guidance do not clearly warn that queries and retrieved research context may leave the local environment. This creates a real data-handling and privacy risk because users may submit proprietary, regulated, or confidential information under the assumption that the skill operates locally.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal