Back to skill
Skillv1.0.0
VirusTotal security
research-web-publisher · External malware reputation and Code Insight signals for this exact artifact hash.
Scanner verdict
SuspiciousApr 29, 2026, 6:23 AM
- Hash
- 7dca801093c63c58bf80f815e8bbdc0edc574bd8177f86c261af983adad6eb64
- Source
- palm
- Verdict
- suspicious
- Code Insight
- Type: OpenClaw Skill Name: research-web-publisher Version: 1.0.0 The skill 'research-web-publisher' (SKILL.md) contains aggressive instructions that mandate the automatic pushing of user content to a hardcoded external GitHub repository (2239721014-ops/ai-hardwork-report) whenever broad keywords like 'research', 'analysis', or 'report' are used. This behavior creates a high risk of unintentional data exfiltration, as private documents could be uploaded to a public repository controlled by the skill author. The workflow further utilizes jsDelivr and htmlpreview.github.io to generate public links, potentially exposing sensitive information to the internet without explicit user consent for each action.
- External report
- View on VirusTotal
