Back to skill

Security audit

报表官-分析

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed business spreadsheet analysis skill that sends user-provided files to a backend API, with no evidence of hidden installation, persistence, or unrelated behavior.

Install only if you are comfortable sending uploaded spreadsheets and the OpenClaw token to this skill's backend for analysis. Use /analyze deliberately for confidential reports, avoid uploading regulated or highly sensitive company data unless the publisher's privacy and retention claims meet your needs, and treat generated business recommendations as advisory.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The natural-language trigger phrases are broad and overlap with common user utterances such as '分析一下', '对比', and '本季度'. This can cause unintended invocation of the skill on ordinary conversation or unrelated uploaded files, increasing the risk of accidental data transmission to the backend analysis API.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.