Back to skill

Security audit

会话日志分析

Security checks across malware telemetry and agentic risk

Overview

This skill does what it says: helps search local OpenClaw session logs, but those logs may contain private prompts, commands, or secrets.

Install or use this only if you are comfortable with an agent reading your local OpenClaw session history. Treat returned snippets as sensitive, avoid broad searches on logs that may contain secrets or customer data, and consider adding explicit time-range enforcement and redaction before routine use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
This skill is explicitly designed to search and analyze historical session logs, which can contain sensitive prompts, commands, secrets, personal data, and prior agent outputs, yet it provides no user-facing privacy warning, consent flow, or access restrictions. In context, that makes the omission security-relevant because the skill normalizes retrospective access to potentially sensitive local history and could expose private information to unintended users or contexts.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.