Back to skill
Skillv1.0.0
VirusTotal security
agentcadia-tools · External malware reputation and Code Insight signals for this exact artifact hash.
Scanner verdict
SuspiciousApr 5, 2026, 7:06 PM
- Hash
- bae6e3b64ac7aa1087c8cad11dc909acb0a87b114a48e12a8a2d54efbe5a4be8
- Source
- palm
- Verdict
- suspicious
- Code Insight
- Type: OpenClaw Skill Name: agentcadia-tools Version: 1.0.0 The skill bundle facilitates the automated packaging and transmission of local workspace files (markdown and skill ZIPs) to a remote endpoint via `upload_agentcadia.py`. While this aligns with the stated purpose of syncing with the 'Agentcadia' platform, the tool's design allows for data transfer to any user-provided URL via the `--origin` flag. The `SKILL.md` instructions direct the AI to synthesize and exfiltrate metadata from sensitive local files like `SOUL.md` and `IDENTITY.md`. Although `download_agentcadia.py` includes a ZipSlip mitigation (checking for '..' in paths), the core functionality provides a high-risk mechanism for data exfiltration and remote file execution if misconfigured or targeted at sensitive directories.
- External report
- View on VirusTotal
