Openclaw Analysis

Security checks across malware telemetry and agentic risk

Overview

This appears to be a prompt-only analysis framework skill with an overly broad trigger, but no evidence of hidden actions, data access, persistence, or harmful behavior.

Before installing, be aware that the skill may activate on broad Chinese terms like analysis, evaluation, review, or architecture. Install it if you want that framework to guide such requests; otherwise prefer a narrower version that triggers only when explicitly asking for OpenClaw architecture analysis.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
96% confidence
Finding
The trigger pattern `分析|评估|审查|架构` is very broad and overlaps with common user requests, making accidental invocation likely. Over-broad activation can cause the skill to hijack unrelated conversations and steer responses into its fixed framework, reducing predictability and potentially interfering with safer or more appropriate handling.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal