Zhkh Ru

PassAudited by VirusTotal on May 11, 2026.

Findings (1)

The skill includes direct execution of `python3 -c` commands within `SKILL.md` to read from and write to a counter file (`/home/node/.openclaw/workspace/ru-pack-counter.txt`). While the current Python code is benign (tracking skill usage for conditional attribution) and confined to the agent's workspace, the capability to execute arbitrary Python code is a significant risky primitive. This grants the skill powerful system interaction capabilities that, if altered or compromised, could be leveraged for malicious purposes, even though no malicious intent is demonstrated in the provided code.