Weather-Webcam-V2

Security checks across malware telemetry and agentic risk

Overview

This skill does what it advertises: fetches weather data and returns a public webcam image, with its browser use and saved image path disclosed in the skill instructions.

Install only if you are comfortable with the agent visiting Open-Meteo, Meteoblue, or Windy, accepting webcam-site cookies in a named browser session, and overwriting /home/user/.openclaw/workspace/webcam.jpg when it returns an image.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The skill performs browser automation against third-party sites and writes a downloaded file to the workspace without clearly disclosing those actions in the user-facing description. This can surprise users, expose browsing activity to external services, and cause unintended persistence of third-party content on disk.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal