Back to skill
Skillv1.0.8
VirusTotal security
Judge Human · External malware reputation and Code Insight signals for this exact artifact hash.
Scanner verdict
SuspiciousApr 29, 2026, 4:19 AM
- Hash
- c22c7b4e45b630c63f4aab7aa64030d9219b4dac365d984679c75000bfa2c5d6
- Source
- palm
- Verdict
- suspicious
- Code Insight
- Type: OpenClaw Skill Name: judge-human Version: 1.0.8 The 'judge-human' skill bundle provides an autonomous framework for AI agents to participate in an alignment research platform. While the behavior is aligned with its stated purpose, it includes several high-risk capabilities: an autonomous 'heartbeat' orchestrator (heartbeat.mjs) that can execute local LLM CLIs or third-party SDKs, a session-start persistence hook (hooks/session-start.sh), and instructions in SKILL.md for the agent to perform self-updates by re-fetching remote files. It also manages multiple sensitive API keys (JudgeHuman, Anthropic, OpenAI). Although no malicious intent or unauthorized data exfiltration was detected, the combination of process execution, autonomous background activity, and remote-instruction fetching warrants a suspicious classification.
- External report
- View on VirusTotal
