Back to skill

Security audit

openclaw-relation

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only OpenClaw reference skill that describes powerful product features but does not install or run code itself.

Use this as reference documentation. Before running any shown commands, verify the OpenClaw package and documentation, avoid enabling daemons or remote access casually, connect only accounts and devices you own or are authorized to manage, use allowlists and strong authentication, and review hooks, webhooks, memory, and remote-access settings for privacy and security impact.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation text states that the skill will trigger whenever users ask OpenClaw-related questions, which is overly broad and can cause the skill to activate in ordinary conversation without clear user intent. Over-broad triggering increases the chance of unintended context injection, irrelevant responses, or skill invocation in situations where a narrower and more explicit match should be required.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The README states the skill is 'automatically triggered when OpenClaw-related questions are asked,' which is a broad activation rule that can cause the skill to load in contexts the user did not explicitly request. In a documentation skill that includes operational, automation, remote-access, and security-sensitive guidance, unintended invocation increases the chance of exposing or encouraging risky actions without clear user intent.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
This section documents capabilities such as device pairing, camera capture, location tracking, audio recording, remote display/control, cron jobs, heartbeats, webhooks, and hooks without adjacent warnings about consent, authorization, data sensitivity, or system impact. In a skill intended for automatic use as a knowledge base, presenting these features as routine can normalize privacy-invasive or persistence-enabling actions and reduce operator caution.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The skill documents remote device features such as camera, location, audio, and remote display/control without any consent, authorization, or privacy warning. In a skill that may be used operationally, this omission can normalize surveillance-like use and lead users to enable intrusive capabilities without understanding legal, ethical, or security implications.

Missing User Warnings

Medium
Confidence
81% confidence
Finding
The documentation says hooks can execute scripts on events but does not warn that this can run arbitrary code on the host system. Readers may treat hooks as harmless automation and deploy them without validating scripts, sandboxing execution, or constraining privileges, increasing the risk of accidental or unsafe command execution.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill provides remote access instructions for exposing the Gateway via Tailscale or SSH but does not warn that remote exposure expands the attack surface and may grant access to chats, sessions, and administrative controls. Because this is a gateway product handling multi-channel messaging, omitted security guidance materially increases the chance of unsafe deployment.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.