Back to skill

Security audit

Noverload - Knowledge Memory

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed Noverload knowledge-library integration that runs read-only by default, with normal token and third-party MCP package trust considerations.

Install only if you trust Noverload and the noverload-mcp npm package. Keep readOnly:true unless you specifically want the agent to save or update library data, store the token carefully, avoid committing or sharing it, and revoke or rotate it if access is no longer needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Session Persistence

Medium
Category
Rogue Agent
Content
1. Sign up at https://noverload.com (free tier available)
2. Go to Settings > Apps
3. Click "New Token" to create a personal access token
4. Copy the token (you won't see it again)

### 2. Configure OpenClaw
Confidence
84% confidence
Finding
create a personal access token 4. Copy the token (you won't see it again) ### 2. Configure OpenClaw Add to `~/.openclaw

VirusTotal

55/55 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.