Trust Assessment
claw-desktop-pet received a trust score of 79/100, placing it in the Mostly Trusted category. This skill has passed most security checks with only minor considerations noted.
SkillShield's automated analysis identified 2 findings: 0 critical, 1 high, 1 medium, and 0 low severity. Key findings include Missing required field: name, External Repository Dependency.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 14, 2026 (commit 13146e6a). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings2
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| HIGH | External Repository Dependency The skill's installation instructions direct users to clone and execute code from an external GitHub repository (https://github.com/kk43994/claw-desktop-pet.git). The security and integrity of this external repository are not part of the current scan, introducing a significant supply chain risk. Malicious changes to the external repository could directly compromise users installing this skill, as the skill's core functionality is sourced from it. For robust security, the skill's source code should be hosted directly within the trusted repository or a verified, version-controlled mirror. If an external dependency is unavoidable, implement strong integrity checks (e.g., cryptographic hashes of expected content) and version pinning for the external repository to prevent unexpected changes. | LLM | SKILL.md:42 | |
| MEDIUM | Missing required field: name The 'name' field is required for claude_code skills but is missing from frontmatter. Add a 'name' field to the SKILL.md frontmatter. | Static | skills/kk43994/claw-desktop-pet/SKILL.md:1 |
Scan History
Embed Code
[](https://skillshield.io/report/d965285d1c1f98ec)
Powered by SkillShield