Back to skill
Skillv1.0.0

VirusTotal security

agentcadia-tools · External malware reputation and Code Insight signals for this exact artifact hash.

Scanner verdict

SuspiciousApr 5, 2026, 7:06 PM
Hash
bae6e3b64ac7aa1087c8cad11dc909acb0a87b114a48e12a8a2d54efbe5a4be8
Source
palm
Verdict
suspicious
Code Insight
Type: OpenClaw Skill Name: agentcadia-tools Version: 1.0.0 The skill bundle facilitates the automated packaging and transmission of local workspace files (markdown and skill ZIPs) to a remote endpoint via `upload_agentcadia.py`. While this aligns with the stated purpose of syncing with the 'Agentcadia' platform, the tool's design allows for data transfer to any user-provided URL via the `--origin` flag. The `SKILL.md` instructions direct the AI to synthesize and exfiltrate metadata from sensitive local files like `SOUL.md` and `IDENTITY.md`. Although `download_agentcadia.py` includes a ZipSlip mitigation (checking for '..' in paths), the core functionality provides a high-risk mechanism for data exfiltration and remote file execution if misconfigured or targeted at sensitive directories.
External report
View on VirusTotal