Back to skill

Security audit

AI Deep Research Agent

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent YouMind research integration, with some normal account, network, and persistence considerations.

Install this only if you trust YouMind and are comfortable sending research topics and generated reports to your YouMind account. Configure the API key in your environment or OpenClaw config rather than pasting it into chat, and be aware that broad phrases like "investigate" may invoke the skill.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger list includes very generic phrases such as "investigate", "analysis report", and multilingual equivalents that commonly appear in ordinary user requests. This can cause the skill to activate unexpectedly, routing normal conversations into a workflow that installs software, uses external networked tooling, and may prompt for API-key setup without the user explicitly intending to invoke this integration.

Static analysis

No suspicious patterns detected.