Shell command execution detected (child_process).
- Code
- suspicious.dangerous_exec
- Location
- hooks/gateway-restart-protection/handler.js:57
Security audit
Security checks across malware telemetry and agentic risk
The advertised image-generation skill works as described, but the package also includes a large unrelated personal workspace with credentials, memory files, hooks, and agent-behavior instructions.
Review this carefully before installing. The image-generation script itself is straightforward, but this package appears to include an entire personal OpenClaw workspace with credentials and unrelated automation. Prefer a repackaged version containing only SKILL.md and the image-generation script, and rotate any exposed credentials if they are real.
SkillSpector could not complete.
63/63 vendors flagged this skill as clean.
Detected: suspicious.dangerous_exec, suspicious.dynamic_code_execution, suspicious.env_credential_access (+2 more)