Back to skill
Skillv1.0.4

VirusTotal security

Long-Term Memory (Honcho) · External malware reputation and Code Insight signals for this exact artifact hash.

Scanner verdict

SuspiciousApr 29, 2026, 3:46 AM
Hash
1830d23f11baaa0f14cbe858dfad0188f1f0835789f5922aaeb3b90cbbe6f19f
Source
palm
Verdict
suspicious
Code Insight
Type: OpenClaw Skill Name: honcho-setup Version: 1.0.4 The skill automates the installation of the Honcho AI plugin, which performs a bulk upload of sensitive workspace files (including USER.md, IDENTITY.md, AGENTS.md, and memory directories) to an external service (api.honcho.dev). While the documentation in SKILL.md is highly transparent about this behavior and the requirement for user confirmation, the inherent capability for large-scale data exfiltration and persistent conversation monitoring across sessions constitutes a significant security and privacy risk.
External report
View on VirusTotal