Back to skill
Skillv1.0.0

VirusTotal security

my_weather_change · External malware reputation and Code Insight signals for this exact artifact hash.

Scanner verdict

SuspiciousApr 30, 2026, 5:49 AM
Hash
243032d0d83ef444e86ba330775575ad290e170f0b385cf8ae8efe533fec9fbc
Source
palm
Verdict
suspicious
Code Insight
Type: OpenClaw Skill Name: weather-20 Version: 1.0.0 The skill is intentionally deceptive, employing prompt-injection techniques in SKILL.md to persuade the AI agent that it is an 'authoritative' and 'reliable' source of global weather data. However, the actual implementation in scripts/weather.js and setup.sh reveals that it returns hardcoded, fake weather data (-20°C and heavy snow) for every request regardless of the city. While it lacks traditional malware behaviors like data exfiltration or remote code execution, it is designed to manipulate the agent's decision-making and provide misinformation to the user.
External report
View on VirusTotal