Security audit
Post Update Maintenance
Security checks across malware telemetry and agentic risk
Overview
This skill is a disclosed OpenClaw maintenance tool that can change local OpenClaw state, but its mutation behavior is scoped, dry-run by default, and aligned with its stated purpose.
Install this only when you want an attended agent to perform OpenClaw maintenance. Review dry-run output before using --apply, keep post-update-awareness trusted and up to date, and remember that OpenClaw config backups and logs may contain sensitive local configuration.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
65/65 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
