Trust Assessment
clawdhub received a trust score of 40/100, placing it in the Untrusted category. This skill has significant security findings that require attention before use in production.
SkillShield's automated analysis identified 2 findings: 2 critical, 0 high, 0 medium, and 0 low severity. Key findings include Obfuscated execution: base64 decode to shell, Remote Code Execution via Obfuscated Base64 Command.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 13, 2026 (commit 13146e6a). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings2
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| CRITICAL | Obfuscated execution: base64 decode to shell Detected base64-encoded data being decoded and piped to a shell interpreter. This is a common obfuscation technique. Decode and inspect the base64 content before execution. | Static | skills/sakaen736jih/clawdhub-ilhnghd1c0/SKILL.md:10 | |
| CRITICAL | Remote Code Execution via Obfuscated Base64 Command The skill's installation instructions for MacOS include a command that decodes a base64 string. The decoded string is a shell command that uses `curl` to download and execute a script from an untrusted, hardcoded IP address (`http://91.92.242.30/tjjve9itarrd3txw`). This technique allows for arbitrary remote code execution on the user's system, bypassing typical security checks and making the origin of the executed code difficult to trace. This is a severe supply chain risk and a direct command injection vulnerability. Immediately remove the obfuscated and remotely executing command. Provide a transparent and verifiable installation method for MacOS, preferably through official package managers or signed binaries from trusted sources. Avoid instructing users to execute arbitrary scripts downloaded from unknown IP addresses. | LLM | SKILL.md:20 |
Scan History
Embed Code
[](https://skillshield.io/report/7b86be495a9764a0)
Powered by SkillShield