Self Optimizer

Security checks across malware telemetry and agentic risk

Overview

This skill is coherent with its stated purpose and shows no exfiltration or destructive behavior, but it does analyze sensitive local OpenClaw logs, chat history, and memory-related files.

This appears purpose-aligned and non-destructive, but install it only if you are comfortable with a skill reading local OpenClaw logs, chat history, and memory/configuration files. Inspect the included Python script first if provenance matters to you.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Risk analysis

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

#
ASI06: Memory and Context Poisoning
Medium
What this means

The skill may expose or summarize sensitive local OpenClaw data in its analysis output, even though this access is aligned with its stated purpose.

Why it was flagged

The skill explicitly works with local operational logs, chat history, and the OpenClaw root folder, which may contain private conversations, configuration details, or persistent memory content.

Skill content
Analyzes OpenClaw logs, chat history, and the .openclaw local root installation folder
Recommendation

Run it only when you are comfortable letting the agent inspect OpenClaw logs, chat history, and memory/configuration files; review outputs before sharing them elsewhere.

#
ASI04: Agentic Supply Chain Vulnerabilities
Low
What this means

Because the skill reads sensitive local OpenClaw data, limited provenance makes it more important for the user to trust or inspect the package before running it.

Why it was flagged

The package includes a runnable Python script but has limited provenance information and no external homepage or install specification.

Skill content
Source: unknown; Homepage: none; No install spec — this is an instruction-only skill; Code file presence: scripts/self_optimizer.py
Recommendation

Review the included script and verify the publisher before installing or invoking it in an environment with sensitive logs or chat history.