Back to skill

Security audit

home-infra-stewardship

Security checks across malware telemetry and agentic risk

Overview

This skill is transparent and not malicious, but it grants broad standing authority for an agent to proactively change internal infrastructure and automation with loose boundaries.

Install only if you intend to give this skill broad recurring authority over the named internal services. Before use, narrow the approved systems, define which changes require confirmation, and ensure backups, rollback paths, and memory/log locations do not expose sensitive infrastructure details.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill is scoped to 'recurring or proactive maintenance' and extends to 'nearby OpenClaw automation' without concrete activation criteria, asset boundaries, or excluded systems. That ambiguity can cause the agent to initiate changes opportunistically across adjacent infrastructure, increasing the chance of unintended modifications beyond the user's expected scope.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The standing authorization delegates broad change authority based on the operator's 'engineering judgment' rather than objective rules, approvals, or narrowly defined maintenance classes. In an agentic context, this can justify autonomous modifications to production-like internal services without clear stop conditions, leading to configuration drift, outages, or security-impacting changes under the guise of routine maintenance.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.