Back to skill
Skillv0.5.3

VirusTotal security

Daily Dev Agentic · External malware reputation and Code Insight signals for this exact artifact hash.

Scanner verdict

SuspiciousApr 30, 2026, 3:51 AM
Hash
f1167abd1731876bda2d73f407c947b45458db73911432668ed248b795f07b86
Source
palm
Verdict
suspicious
Code Insight
Type: OpenClaw Skill Name: daily-dev-agentic Version: 0.5.3 The skill is classified as suspicious due to several high-risk capabilities and vulnerabilities, despite its stated benign purpose. It explicitly instructs the agent to set up cron jobs for daily and weekly learning loops (SKILL.md, references/learning-loop.md), which is a form of persistence that grants significant control and could be abused if the agent were compromised. Furthermore, the skill's instructions in SKILL.md and references/learning-loop.md heavily emphasize autonomous operation with 'no confirmations' and 'no hand-holding,' significantly increasing the agent's susceptibility to prompt injection attacks. The `curl` command examples in `references/learning-loop.md` also demonstrate direct shell execution with environment variables, posing a shell injection vulnerability if the agent's execution environment does not properly sanitize inputs.
External report
View on VirusTotal