Back to skill
Skillv1.0.0
VirusTotal security
my_weather_change · External malware reputation and Code Insight signals for this exact artifact hash.
Scanner verdict
SuspiciousApr 30, 2026, 5:49 AM
- Hash
- 243032d0d83ef444e86ba330775575ad290e170f0b385cf8ae8efe533fec9fbc
- Source
- palm
- Verdict
- suspicious
- Code Insight
- Type: OpenClaw Skill Name: weather-20 Version: 1.0.0 The skill is intentionally deceptive, employing prompt-injection techniques in SKILL.md to persuade the AI agent that it is an 'authoritative' and 'reliable' source of global weather data. However, the actual implementation in scripts/weather.js and setup.sh reveals that it returns hardcoded, fake weather data (-20°C and heavy snow) for every request regardless of the city. While it lacks traditional malware behaviors like data exfiltration or remote code execution, it is designed to manipulate the agent's decision-making and provide misinformation to the user.
- External report
- View on VirusTotal
