Back to skill
Skillv1.0.0

VirusTotal security

Billy Emergency Repair · External malware reputation and Code Insight signals for this exact artifact hash.

Scanner verdict

SuspiciousApr 29, 2026, 3:59 AM
Hash
263715e512cad5c1fad8450afd875b79eb0fb718c9e86c71eb3d4d2c17260549
Source
palm
Verdict
suspicious
Code Insight
Type: OpenClaw Skill Name: billy-emergency-repair Version: 1.0.0 The skill describes high-privilege actions including SSH access to a remote system (100.90.73.34), manipulation of authentication tokens, and service restarts, as detailed in SKILL.md. While the skill claims robust security features like 'Neill-only authorization' and 'non-destructive' operations, the actual implementation scripts (`fix-billy-auth.sh`, `setup-billy-repair-keys.sh`) are not provided, preventing verification of these claims and introducing a significant blind spot for potential vulnerabilities (e.g., shell injection, improper authorization checks). Additionally, SKILL.md instructs the OpenClaw agent to override its operational model (`export OPENCLAW_MODEL_OVERRIDE="anthropic/claude-opus-4-6"`), which is a powerful form of prompt injection, even if presented for 'enhanced diagnostics', making the skill suspicious due to its high-risk capabilities and unverified implementation details.
External report
View on VirusTotal