agent-council

Security checks across malware telemetry and agentic risk

Overview

The skill's files and runtime instructions align with its stated purpose (creating agents and managing Discord channels); it reads and patches the local OpenClaw gateway config and the user's workspace, which is expected behavior — review and back up configs before use.

This skill will modify your OpenClaw gateway config, create files in any workspace you point it at, call the Discord API using the bot token stored in ~/.openclaw/config.json, and can add cron jobs that cause agents to write memory files. Before installing or running: 1) Back up ~/.openclaw/config.json and your gateway config. 2) Inspect the three scripts (they are included) and run them first with test workspaces or dry-run copies. 3) Confirm the Discord bot token and permissions in your config are appropriate. 4) When scripts print gateway config patches, review them before applying (openclaw gateway config.patch). 5) Be aware that workspace search-and-replace can modify many files — run with a safe --workspace path first. If you need more assurance, run the scripts in an isolated environment or container and confirm they only perform the described operations.

SkillSpector

By NVIDIA

SkillSpector findings are pending for this release.

VirusTotal

No VirusTotal findings

View on VirusTotal