openclaw-version-monitor

Security checks across malware telemetry and agentic risk

Overview

This skill is an instruction-only release monitor that fetches public OpenClaw release notes and formats notifications for Telegram and Feishu.

Before installing, confirm that Telegram chat ID 8290054457 and the Feishu destination are yours, use limited-purpose bot or app credentials, and only enable scheduled checks if you want automatic release notifications to those services.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly sends content to Telegram and Feishu but does not disclose that release notes and destination identifiers will be transmitted to third-party services. This creates a privacy and data-governance risk because users may not realize that fetched content and recipient metadata leave the local environment and are shared with external platforms.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal