OpenClaw 成长追踪器

Security checks across malware telemetry and agentic risk

Overview

This is a local personal growth tracker, but it asks to automatically record ongoing OpenClaw conversations or usage after setup without clear limits or stop/delete controls.

Review before installing. Use it only if you are comfortable with local automatic tracking of OpenClaw activity, and avoid enabling it during sensitive conversations unless your agent provides clear controls to pause tracking, inspect stored data, and delete records.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
96% confidence
Finding
The statement that future conversations will be 'automatically recorded' after initialization creates ambiguous, persistent data collection with no clear boundaries, exclusions, or renewed consent. In a conversational assistant, this can lead to over-collection of sensitive content from unrelated chats and unexpected long-term logging of user activity.

Missing User Warnings

High
Confidence
98% confidence
Finding
The skill explicitly describes automatic recording of conversations and usage data without a prominent privacy warning, consent flow, or explanation of what sensitive data may be captured. This is dangerous because users may unknowingly expose personal, confidential, or regulated information into a local log simply by continuing normal use after initialization.

Ssd 3

Medium
Confidence
97% confidence
Finding
Instructing the system to automatically record every subsequent conversation and usage data establishes a broad logging behavior that can capture sensitive user inputs outside the user's immediate intent. Even if stored locally, comprehensive transcript-style collection increases exposure to privacy harm, accidental retention of secrets, and later misuse or unauthorized access on the host system.

Ssd 3

Medium
Confidence
89% confidence
Finding
Framing every conversation, task, breakthrough, and act of persistence as something to be recorded encourages excessively broad collection by design. This normalization of comprehensive interaction logging makes the skill more dangerous in context because it invites capturing more user data than is necessary for a growth-tracking feature.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal