Boxed FFmpeg

PassAudited by VirusTotal on Apr 3, 2026.

Findings (1)

The skill provides media processing capabilities by instructing the agent to download a remote WASM binary from a personal GitHub repository (guyoung/wasm-sandbox-openclaw-skills) and execute it using a sandbox tool. While this behavior is consistent with the stated goal of providing a 'boxed' FFmpeg environment, the automated downloading and execution of remote payloads (SKILL.md) is a high-risk capability. No clear evidence of malicious intent, such as data exfiltration or unauthorized access, was found, but the reliance on an unverified external binary warrants a suspicious classification.