Back to skill

Security audit

Late Night Companion

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only emotional support skill that clearly discloses its late-night proactive check-in behavior, but users should understand it may initiate sensitive conversations when they are active or online.

Install this only if you want a companion skill that may send a gentle late-night check-in when you are active or online. Confirm your OpenClaw environment exposes DND, disable, and memory-clearing controls, especially for saved emotional context or risk flags. This should not be treated as professional or emergency mental-health support.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill is explicitly designed to activate proactively based on late-night presence and recent activity, without a clear user-initiated invocation. In an emotional-support context, unsolicited outreach can be privacy-invasive, emotionally manipulative, or trigger unwanted engagement when the user merely happens to be online, especially because the trigger conditions are broad and inferred from behavior rather than explicit consent.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The session-start rule enters 'Late-Night mode' whenever the user is online during a broad local-time window and DND is not set, which does not establish intentional activation. Because this skill handles sensitive emotional states, treating ordinary online presence as consent increases the risk of boundary violations, mistaken interventions, and retention/use of sensitive inferred context without a sufficiently clear trigger.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.