report-clawhub-malicious-skill
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references downloading benchmark datasets from Hugging Face, which is a recognized and trusted platform for machine learning assets.
- [COMMAND_EXECUTION]: Instructions guide the user through using project-specific tools like
clawscanto perform static analysis on files. The workflow includes explicit safety warnings to ensure suspicious code is analyzed as data and never executed. - [DATA_EXFILTRATION]: The skill identifies and enforces a safety boundary by requiring that sensitive details, such as exploit payloads and reproduction notes, be kept within private GitHub vulnerability reports rather than public channels.
Audit Metadata