vardoger — Analyze History

Security checks across malware telemetry and agentic risk

Overview

This skill is transparent about its goal, but it reads broad past conversation history and writes persistent global assistant personalization, so users should review it carefully before installing.

Install only if you want an assistant to inspect past OpenClaw conversations and turn them into persistent global instructions. Verify the vardoger CLI source and version, approve only the expected vardoger commands, review the generated markdown before keeping it, and know where to remove the generated personalization file if it captures anything sensitive or unwanted.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The activation condition is overly broad because merely mentioning "vardoger" can trigger a workflow that reads historical conversations and writes persistent personalization files. This increases the chance of unintended execution of a high-sensitivity skill without clear user intent or informed consent.

Ssd 3

High
Confidence
96% confidence
Finding
The skill is explicitly designed to read the user's full conversation history from platform session directories and derive behavioral profiles from it. Even if intended as personalization, this creates a powerful data-exposure pathway because sensitive prior content may be processed, summarized, and reused beyond its original context.

Ssd 3

High
Confidence
95% confidence
Finding
The skill directs the assistant to read batch outputs containing raw conversation data and produce summaries of behavioral signals. Summarization does not eliminate risk: sensitive data can be retained, inferred, or transformed into derived artifacts that persist or are shown to the user.

Ssd 3

High
Confidence
97% confidence
Finding
Writing synthesized personalization into a persistent global rules file extends the lifetime and scope of information derived from past conversations. This can cause sensitive preferences, private facts, or inferred traits to be silently reused across future sessions and contexts, amplifying privacy and data-retention risk.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal