Back to skill

Security audit

Openclaw Thumbnail Forge

Security checks for vulnerabilities and agentic risk

Overview

This is a local thumbnail-generation skill that processes user-chosen media files and does not show hidden network, credential, persistence, or destructive behavior.

Install dependencies only from trusted package sources. Run the scripts on media files and output folders you choose, and expect existing output files at those paths to be overwritten when using the same filenames.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.