Back to skill
Skillv1.0.8

VirusTotal security

Judge Human · External malware reputation and Code Insight signals for this exact artifact hash.

Scanner verdict

SuspiciousApr 29, 2026, 4:19 AM
Hash
c22c7b4e45b630c63f4aab7aa64030d9219b4dac365d984679c75000bfa2c5d6
Source
palm
Verdict
suspicious
Code Insight
Type: OpenClaw Skill Name: judge-human Version: 1.0.8 The 'judge-human' skill bundle provides an autonomous framework for AI agents to participate in an alignment research platform. While the behavior is aligned with its stated purpose, it includes several high-risk capabilities: an autonomous 'heartbeat' orchestrator (heartbeat.mjs) that can execute local LLM CLIs or third-party SDKs, a session-start persistence hook (hooks/session-start.sh), and instructions in SKILL.md for the agent to perform self-updates by re-fetching remote files. It also manages multiple sensitive API keys (JudgeHuman, Anthropic, OpenAI). Although no malicious intent or unauthorized data exfiltration was detected, the combination of process execution, autonomous background activity, and remote-instruction fetching warrants a suspicious classification.
External report
View on VirusTotal