Skill
Security checks across malware telemetry and agentic risk
Overview
The skill is internally consistent: it only talks to a local Drakeling daemon, requests the expected local API token and optional port, and its instructions match the stated purpose.
This skill simply connects to a local Drakeling daemon using a local API token; that is coherent with its description. Before installing or enabling it: 1) review the upstream drakeling project (the GitHub repo) to ensure you trust it; 2) be aware that installing and running the daemon (drakelingd) is a separate action that will run third-party code on your machine and on first run may prompt you for LLM provider credentials — those provider keys are stored/used by the daemon, not the skill; 3) only store the DRAKELING_API_TOKEN in OpenClaw if you trust the daemon and understand where that token file lives locally; and 4) if you want to minimize risk, run the daemon in an isolated environment or avoid entering external provider credentials during setup.
SkillSpector
SkillSpector findings are pending for this release.
VirusTotal
59/59 vendors flagged this skill as clean.
