OpenClaw X

Security checks across malware telemetry and agentic risk

Overview

This skill is for controlling an X/Twitter account, but it asks users to run an external executable with exported browser cookies and exposes account-changing actions.

Install only if you trust the external executable and are comfortable giving it X/Twitter session-cookie access. Use a secondary account where possible, keep cookies.json private, stop the localhost service when done, and require explicit approval before any post, like, retweet, or bookmark.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill instructs users to export X/Twitter authentication cookies from Chrome and place them next to a downloaded executable, but provides no warning about the sensitivity of those cookies or the risk of account takeover if they are exposed. Because the executable then exposes account functionality through a local API, any local process or malware able to reach that service may be able to act as the user.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill documents account-modifying operations such as posting, liking, retweeting, and bookmarking without warning users that these actions can change public account state and may be irreversible or reputation-impacting. In an agent setting, omission of consent and confirmation guidance increases the chance of unintended or automated actions being performed on behalf of the user.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal