Book Skill Generator
PassAudited by VirusTotal on May 13, 2026.
Findings (1)
The skill bundle is designed to extract methodologies from books and generate new OpenClaw skills. It is classified as suspicious due to a potential shell injection vulnerability in SKILL.md, where the agent is instructed to execute a system command (`python -m scripts.package_skill {methodology-name}`) using variables derived from external book content or user input. Additionally, the required 'scripts' package mentioned in the command is missing from the bundle's file list, and the skill relies on broad permissions including web searching, file reading, and command execution to function.
