OpenClawMP

Security checks across malware telemetry and agentic risk

Overview

This appears to be a real OpenClaw Marketplace CLI and guide, but it needs Review because it can change local agent installs and account state and has unsafe command/path handling.

Install only if you intentionally want an agent to use OpenClaw Marketplace. Confirm any install, publish, comment, unbind, or delete-account action yourself; keep API keys private; avoid automatic global updates; and review downloaded assets before letting them load in future agent sessions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The activation terms are very broad and include generic marketplace-related phrases, making accidental invocation likely in unrelated conversations. In this skill's context, accidental activation is more dangerous because the content covers authenticated network operations, installation, publishing, and account actions.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal