Back to skill

Security audit

Clinical Tempo

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Clinical Tempo context helper with optional reminder hooks and no evidence of hidden data access, exfiltration, or destructive behavior.

Install this for Clinical Tempo work if you want repo-context reminders. Keep activation scoped to the Clinical Tempo workspace, enable optional hooks only where repeated bootstrap reminders are desired, review any proposed CLAWHUB.md entries for accuracy and secrets, and assess the separate Anyway OpenClaw plugin before installing it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
79% confidence
Finding
The detection triggers include many broad terms such as Tempo, 402, NHS, OpenClaw, and 8787, which can appear in unrelated conversations. Over-broad auto-activation can inject irrelevant instructions and shell-oriented operational guidance into unrelated tasks, increasing prompt-surface area and the chance of unintended tool use or context poisoning.

Vague Triggers

Medium
Confidence
75% confidence
Finding
The trigger 'user uploads ClawHub / OpenClaw / Copilot context questions' is ambiguous and underspecified, so the skill may activate based on loosely related uploaded material. This can cause unnecessary context injection and increase the likelihood that unrelated files are interpreted through this skill's operational guidance, though the impact is lower than the broad keyword trigger set.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.