Back to skill

Security audit

OrgX Marketing Agent

Security checks for vulnerabilities and agentic risk

Overview

This is a small instruction-only marketing skill that does not include code, install hooks, credential access, persistence, or hidden behavior.

This appears reasonable to install for marketing drafting and campaign planning. If your OpenClaw environment later grants OrgX tools that can publish, report externally, or apply changes, review those tool permissions separately and keep human approval around any mutation or public posting workflow.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.