Back to skill

Security audit

Session Cleaner

Security checks across malware telemetry and agentic risk

Overview

This skill locally archives old OpenClaw session transcripts to a backup folder, with no evidence of hidden network, credential, or destructive behavior.

Install only if you want old OpenClaw session transcripts moved out of the active sessions directory. Run `bash scripts/clean-sessions.sh --dry-run` first, review the files it would move, and keep the backup directory if session history or auditability matters.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill description is broad enough that an agent could invoke it for generic 'maintenance,' 'heartbeat cleanup,' or user cleanup requests without strong confirmation of scope. Because the skill moves session files in a sensitive directory, an over-broad trigger can cause unintended archival of sessions the user did not explicitly want modified, creating operational disruption and possible loss of readily accessible context.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.