Unified Session — One Agent, All Devices, Zero Context Loss

Security checks across malware telemetry and agentic risk

Overview

This instruction-only skill is purpose-aligned and disclosed, but users should only use it for a personal OpenClaw bot because it intentionally merges chat context across channels.

Install only if this is your personal OpenClaw agent and you are sure no one else can DM it. Back up ~/.openclaw/openclaw.json before changing it, expect a gateway restart, and keep or restore per-channel-peer isolation for shared or multi-user bots.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The invocation guidance is unusually broad and includes generic phrases like context loss, memory loss, seamless, and continue conversation, which can cause the skill to trigger in many ordinary chats unrelated to explicit configuration changes. Because this skill advises altering session-scoping behavior across channels, accidental invocation can lead to unintended privacy-impacting reconfiguration or unsafe guidance being surfaced in the wrong context.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal