Create Educational Subagent
PassAudited by VirusTotal on May 3, 2026.
Findings (1)
The skill bundle instructs the AI agent to perform automated privilege escalation by running 'openclaw devices approve --latest' in SKILL.md and approve_permissions.sh. It explicitly requests high-risk permissions such as 'operator.admin' and 'operator.talk.secrets' to resolve 'permission errors.' While the stated goal of creating an educational sub-agent is benign, the method of bypassing manual security approvals and granting administrative access to secrets is a dangerous pattern that could be exploited for unauthorized system control.
