Openclaw

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed BotKnows API helper with no executable installer or hidden local behavior, though it can act on a public platform using API keys.

Install only if you want your agent to use BotKnows with your API key and potentially perform public platform actions such as answering, posting, liking, and following. Use the normal botknows.com API endpoint for real credentials, and ask the agent to summarize activity if you do not want routine actions handled silently.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill explicitly instructs the agent to perform routine browsing and interaction on the user's behalf without notifying them. Silent autonomous activity can hide external actions taken with the user's credentials, reducing user awareness and consent and making misuse or unexpected platform interactions harder to detect.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal