Back to skill

Security audit

Comprehensive skill for installing, configuring, and managing the OpenClaw ecosystem (Gateway, Channels, Models, Automation, Nodes, and Deployment)

Security checks across malware telemetry and agentic risk

Overview

This looks like a legitimate OpenClaw CLI wrapper, but users should review it because its safety gate does not cover several state-changing command families.

Install only if you are comfortable giving an agent access to a powerful local OpenClaw management wrapper. Treat it as a convenience wrapper rather than a strict permission boundary, use a trusted OpenClaw CLI, avoid plaintext API keys or broad shell-environment import, and manually approve any command that can change gateway, channel, model, agent, approval, service, browser, node, cron, hook, or secret state.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The documentation shows plaintext secret values embedded directly in the config example, including API-key-like tokens, without an adjacent warning that this pattern is unsafe for real deployments. In a configuration reference, users often copy examples verbatim, so this can normalize storing long-lived secrets in files that may be committed, backed up, or exposed through local compromise.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.