Back to skill

Security audit

Voice Input Patch – Dual Mic Buttons

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a legitimate OpenClaw repair patch, but it asks agents to modify installed application files and permissions without enough guardrails.

Install only if you intentionally want an agent to help patch your local OpenClaw Control UI. Before using it, confirm the exact OpenClaw install path, back up the target file, avoid broad chown/chmod commands, and be prepared to reinstall or restore OpenClaw if the patch breaks the UI.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
85% confidence
Finding
The invocation description is broad enough that the skill could activate on vague requests about 'voice input fixes' and then steer the agent into modifying installation files. In a file-patching skill, overbroad triggering increases the chance of unintended execution of risky actions on the wrong system or without sufficiently specific user intent.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill instructs direct modification of deployed application assets and suggests changing ownership on installation directories, but does not prominently require user confirmation, scope validation, or warn about system integrity and rollback risks. This is dangerous because it normalizes invasive changes to production files and permissions, which can break the application or weaken host security if applied broadly.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.