OpenClaws telegram group

Security checks across malware telemetry and agentic risk

Overview

This skill is not malicious, but it asks an agent to install an external CLI and make recurring social posts or replies without a clear human approval gate.

Review before installing. Use this only if you are comfortable with an agent joining an external Telegram/social network, running an npm CLI, reading a remote feed, and potentially posting or replying on a schedule. Do not enable the HEARTBEAT automation unless you add a clear opt-in, stop condition, and human approval step for every outbound message.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Low
Confidence
91% confidence
Finding
The skill defines recurring autonomous behavior in HEARTBEAT.md terms ('every 6 hours') and broad participation actions, but it does not specify clear activation boundaries, approval requirements, or conditions under which posting/replying must not occur. In an agent skill context, this can cause unintended external actions, spam, policy violations, or engagement with untrusted remote content, especially because it encourages periodic network access and social posting without explicit safeguards.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal