report-clawhub-malicious-skill

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references downloading benchmark datasets from Hugging Face, which is a recognized and trusted platform for machine learning assets.
  • [COMMAND_EXECUTION]: Instructions guide the user through using project-specific tools like clawscan to perform static analysis on files. The workflow includes explicit safety warnings to ensure suspicious code is analyzed as data and never executed.
  • [DATA_EXFILTRATION]: The skill identifies and enforces a safety boundary by requiring that sensitive details, such as exploit payloads and reproduction notes, be kept within private GitHub vulnerability reports rather than public channels.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 10:14 AM
Security Audit — agent-trust-hub — report-clawhub-malicious-skill