office-quotes

PassAudited by VirusTotal on May 12, 2026.

Overview

Type: OpenClaw Skill Name: office-quotes Version: 1.2.3 The skill is classified as suspicious due to the import of `child_process.execSync` in `scripts/office-quotes.js`, which grants the capability for arbitrary command execution, even though it is not currently utilized in the provided code. Additionally, the script uses `playwright` to launch a full Chromium browser instance for SVG rendering, which is a powerful and resource-intensive operation that significantly expands the attack surface, despite being used for a plausible purpose (image conversion). While the skill's stated purpose is benign, these high-risk capabilities prevent a 'benign' classification.