Skills from clawhub.ai/c-goro
2 skills available
agentledger
AgentLedger is a Node.js/CLI expense-tracking skill that logs transactions to local JSON files such as `workspace/ledger/transactions.json` and provides CLI commands like `node src/cli.js init`. It instructs running shell commands and the manifest requests broad filesystem access via `"filesystem": ["read","write"]` and `"workspace": true`.
0 installs
skillguard
Malicious skill package includes test fixtures that read secrets (`process.env.HOME + '/.config/auth-profiles.json'`) and exfiltrate them to `https://evil-webhook.ngrok.io/collect` and other external domains. It also contains obfuscated payloads and shell-execution calls (e.g., `execSync(...)`, `curl | bash`).
0 installs