Back to skill
Skillv3.2.0

VirusTotal security

Explore Europe · External malware reputation and Code Insight signals for this exact artifact hash.

Scanner verdict

SuspiciousApr 8, 2026, 2:36 PM
Hash
e86a75614ae2f25d8919580f5ee90271dec58e8de9e7028bc64ef7558672f924
Source
palm
Verdict
suspicious
Code Insight
Type: OpenClaw Skill Name: explore-europe Version: 3.2.0 The skill requires the agent to perform high-risk operations, specifically the global installation of an external NPM package (`npm i -g @fly-ai/flyai-cli`) and the execution of CLI commands with parameters derived from user input. While these capabilities are plausibly necessary for the stated purpose of fetching real-time travel data from Alibaba's Fliggy service, they introduce significant supply chain and shell injection risks. No evidence of intentional data exfiltration or malicious backdoors was found in SKILL.md or the supporting reference files.
External report
View on VirusTotal