Back to skill
Skillv0.1.3

VirusTotal security

Lybic Sandbox · External malware reputation and Code Insight signals for this exact artifact hash.

Scanner verdict

SuspiciousApr 28, 2026, 8:18 AM
Hash
4a63b834a088bfdafb2628069a1a055bde438109e2a857b2b2002d953a0e40be
Source
palm
Verdict
suspicious
Code Insight
Type: OpenClaw Skill Name: lybic-sandbox Version: 0.1.3 The skill provides extensive capabilities for arbitrary code execution, GUI automation (mouse, keyboard, touch), file system access (download, read, write), and network operations (port mapping) within a Lybic cloud sandbox. While these are high-risk capabilities, they are explicitly aligned with the stated purpose of controlling a 'disposable cloud computer' for automation workflows. There is no clear evidence of intentional harmful behavior targeting the host system, such as credential theft, data exfiltration from the host, persistence mechanisms, or malicious prompt injection against the agent to subvert its core directives. The instructions in SKILL.md and the example code (e.g., examples/01_execute_code.py, examples/03_file_processing.py, examples/06_http_port_mapping.py) demonstrate these powerful features, which, while necessary for the skill's function, inherently carry a high risk if misused by the agent or a malicious prompt.
External report
View on VirusTotal