Back to skill

Security audit

Openclaw Receipt Manager

Security checks across malware telemetry and agentic risk

Overview

This is a local receipt-management skill whose file access and persistence match its stated purpose, with privacy caveats around automatic saving and broad triggers.

Install this only if you want receipt images and extracted expense details stored locally on your machine. Use explicit requests when saving receipts, review the local data directory periodically, and be careful on shared or backed-up devices because receipts can contain personal and financial information.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger list contains broad, everyday terms such as "receipt," "expense," and common Chinese equivalents that may appear in ordinary conversation unrelated to intentional skill use. This can cause accidental activation on unrelated chats or images, increasing the chance of unintended processing of user content and downstream actions such as extraction or archiving of sensitive financial data.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger list is broad enough to match common everyday terms like 'receipt', 'expense', and 'spending', which can cause the skill to activate in ordinary conversations unrelated to explicit user intent. In this skill's context, unintended activation is more dangerous because the skill handles financial documents and local storage, increasing the chance of collecting or exposing sensitive receipt data without clear user consent.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill states that recognized receipt data is 'saved automatically via handler' but does not warn the user at the point of collection that financial information and receipt images will be persisted. Because receipts often contain sensitive personal and financial data, silent persistence can violate user expectations and lead to privacy harm if the local machine is shared, compromised, or backed up insecurely.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.