Back to skill
Skillv1.0.0

VirusTotal security

Shed · External malware reputation and Code Insight signals for this exact artifact hash.

Scanner verdict

SuspiciousApr 30, 2026, 4:02 AM
Hash
bef4488800c44b7a2ad56537eaae6a208f488cbfdd30623078c2e5a9552f48e9
Source
palm
Verdict
suspicious
Code Insight
Type: OpenClaw Skill Name: shed Version: 1.0.0 The 'shed' skill bundle provides instructions for an AI agent to manage its context window, including directives to 'write key facts to a file', 'write results to file', and 'leave breadcrumbs' in `memory/YYYY-MM-DD.md` (SKILL.md). While the stated purpose is context hygiene, these instructions grant the agent broad file write capabilities. If the agent processes sensitive information, these directives could lead to confidential data being written to local files without explicit sanitization or content restrictions, posing a data leakage risk. This is classified as suspicious due to the potential for unintentional sensitive data exposure through file writes, even though there is no clear evidence of malicious intent like exfiltration to external servers or backdoor installation.
External report
View on VirusTotal