Back to skill

Security audit

Skill Safe Install (L0 Strict)

Security checks across malware telemetry and agentic risk

Overview

This is a text-only safety checklist for reviewing and installing other OpenClaw skills, with clear consent gates before installs or trust-list changes.

Reasonable to install if you want a stricter workflow before installing other skills. When using it, still review each target skill’s permissions carefully, treat the temporary workdir as limited isolation rather than a full security sandbox, and only approve persistent trust-list changes when you intentionally want future trust for that skill.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal