Nonopost

PassAudited by VirusTotal on May 12, 2026.

Findings (1)

The skill instructs the AI agent to perform file system read/write operations in the user's home directory (`~/.openclaw/nonopost/identity.json`) and explicitly execute a shell command (`cat ~/.openclaw/nonopost/identity.json | jq -r .authorName`) as detailed in `SKILL.md`. While these actions are presented as necessary for the skill's stated purpose of identity preservation, the explicit instruction for shell command execution represents a high-risk capability that could be leveraged for malicious purposes if the command were altered or if the agent were further prompted to execute arbitrary commands.