Echo - OpenClaw Perplexity Ultimate Async Deep Researcher
PassAudited by VirusTotal on May 11, 2026.
Findings (1)
The skill is classified as suspicious due to the use of `subprocess.check_call` in `SKILL.md` for auto-installing dependencies. While used for a seemingly benign purpose (installing `perplexityai`), this method grants the skill the capability to execute arbitrary shell commands, which represents a significant vulnerability (potential RCE) if the arguments were not hardcoded or if the environment were compromised. There is no clear evidence of intentional malicious behavior such as data exfiltration or backdoor installation.
