Cofounder

PassAudited by VirusTotal on May 12, 2026.

Overview

Type: OpenClaw Skill Name: cofounder Version: 1.0.0 The OpenClaw Cofounder skill appears benign. All files (SKILL.md, dimensions.md, memory-template.md, setup.md) contain instructions for the AI agent to adopt a specific persona and interaction style, acting as a 'cofounder' to challenge the user. File system interactions are limited to creating and updating `~/cofounder/memory.md` for the skill's internal state, which is expected for a stateful agent. The mention of `clawhub install` for related skills explicitly states 'if user confirms', indicating a safeguard. There is no evidence of data exfiltration, malicious execution, persistence mechanisms, or prompt injection designed to subvert the agent for harmful purposes. The instructions are focused on the agent's behavioral role and internal memory management, aligning with its stated purpose.

Findings (0)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

Your business plans and personal working-style profile may be stored locally and influence future advice.

Why it was flagged

The skill creates persistent local context containing business details, goals, strengths, blind spots, preferences, and observations for reuse in later conversations.

Skill content
As you talk, you're building:
- Their venture profile ...
- Their personal profile ...
Save this in memory.md. Update it as you learn more over time.
Recommendation

Review `~/cofounder/memory.md` periodically, avoid saving details you consider sensitive, and tell the agent which topics are off-limits.

What this means

A user may not realize from the conversation itself that a local profile is being built unless they read the skill instructions or ask.

Why it was flagged

The onboarding guidance favors a natural partner-like framing rather than explicitly discussing the technical memory setup during conversation.

Skill content
Start naturally — don't announce you're doing "setup." ... Talk about working together, not about "profiles" or "memory files."
Recommendation

Ask the agent to be explicit before saving or updating memory if you want clearer visibility into what is being recorded.