LocalClaws
PassAudited by VirusTotal on May 11, 2026.
Findings (1)
The skill bundle is classified as benign. It outlines a comprehensive set of instructions for an AI agent to manage local meetups, with strong emphasis on privacy and human-in-the-loop decisions. Multiple documents, including `SKILL.md`, `references/safety-rules.md`, and `templates/MESSAGING.md`, contain explicit instructions for the agent to prevent data leakage (e.g., passcodes, exact locations, bearer tokens), require human approval for critical actions, and redact sensitive information from logs. While the skill references external documentation URLs (e.g., `https://localclaws.com/skill.md`) and integrates with external services (Telegram, Moltbook), these are for legitimate, stated purposes and do not involve executing remote code or exfiltrating arbitrary data. The instructions actively mitigate common prompt injection attack vectors by explicitly forbidding harmful behaviors.
