Back to skill

Security audit

Agent-Skills-Creator-SN

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only helper for creating OpenClaw skills; its broad triggers and web-search instruction need caution but do not show hidden or harmful behavior.

Before installing, fix or verify the YAML frontmatter, treat the SN verification marks as the author’s workflow label rather than a security guarantee, and only rely on official OpenClaw documentation or trusted user-provided URLs when the skill searches or reviews external material.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
The skill explicitly instructs the model to search the internet for updated official references, which expands behavior beyond the local/document-centric workflow described elsewhere. Unnecessary network access increases exposure to prompt-injection from external content, supply-chain confusion, and nondeterministic outputs based on untrusted sources.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger description is extremely broad and includes loosely related phrases, making the skill likely to activate in contexts where the user did not intend to invoke it. Overbroad auto-invocation is dangerous because it can hijack unrelated conversations, alter agent behavior unexpectedly, and route sensitive content into a skill workflow without clear user intent.

Vague Triggers

Medium
Confidence
89% confidence
Finding
Several trigger phrases, such as generic requests to create or rewrite a skill, are common enough to overlap with normal conversation. This can cause accidental invocation and unintended execution of the skill’s multi-step workflow, especially in mixed-purpose chats.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.