Civic Google

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Google Workspace OAuth helper that can enable powerful account actions after consent, so it looks coherent but should be installed only if you trust Civic and the external plugin.

Install this only if you trust Civic and the @civic/openclaw-google package to broker Google OAuth access. Authorize only the scopes you need, review agent requests before write/delete/share/send/transfer/deploy commands, protect CIVIC_TOKEN like an API key, avoid setting a custom proxy URL unless you control it, and revoke Civic or Google access when you stop using the integration.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal