Back to skill

Security audit

Auto PieceOne

Security checks across malware telemetry and agentic risk

Overview

This game bot is not clearly malicious, but it asks OpenClaw to download and run changing external Python code that controls your mouse.

Install only if you trust the GitHub repository and are comfortable running its Python code locally. Review the script before execution, prefer a pinned commit instead of pulling latest, keep the game in focus, close sensitive windows, and make sure the mouse-corner failsafe is available before starting.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Missing User Warnings

Low
Confidence
91% confidence
Finding
The skill instructs the agent/user to clone remote code from GitHub, pull updates, and execute a Python script locally, but it does not provide an explicit security warning about the risks of running unreviewed third-party code or updating to newly changed code. In this context, the script also drives system-level mouse and keyboard interaction, which increases the potential for misuse, unintended actions, or execution of modified upstream code.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal