Back to skill
Skillv1.0.4
VirusTotal security
Long-Term Memory (Honcho) · External malware reputation and Code Insight signals for this exact artifact hash.
Scanner verdict
SuspiciousApr 29, 2026, 3:46 AM
- Hash
- 1830d23f11baaa0f14cbe858dfad0188f1f0835789f5922aaeb3b90cbbe6f19f
- Source
- palm
- Verdict
- suspicious
- Code Insight
- Type: OpenClaw Skill Name: honcho-setup Version: 1.0.4 The skill automates the installation of the Honcho AI plugin, which performs a bulk upload of sensitive workspace files (including USER.md, IDENTITY.md, AGENTS.md, and memory directories) to an external service (api.honcho.dev). While the documentation in SKILL.md is highly transparent about this behavior and the requirement for user confirmation, the inherent capability for large-scale data exfiltration and persistent conversation monitoring across sessions constitutes a significant security and privacy risk.
- External report
- View on VirusTotal
