Back to skill

Security audit

OpenClaw 心跳设计器

Security checks across malware telemetry and agentic risk

Overview

This skill is a planning guide for HEARTBEAT.md and cron schedules, with no executable code or hidden install behavior, but users should review generated schedules and sensitive monitoring ideas before enabling them.

Install if you want help drafting heartbeat checklists and cron schedules. Before enabling generated jobs, verify the timezone, limit active checks, avoid putting secrets in HEARTBEAT.md, and require explicit confirmation before any workflow changes email labels, subscriptions, financial data, passwords, account settings, or backups.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrases are broad, generic, and overlap with ordinary scheduling and automation requests, which makes accidental or unintended invocation plausible. In an agent setting, this can cause the skill to activate in contexts where the user did not intend heartbeat/cron generation, potentially leading to inappropriate recommendations or automated task setup.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The skill presents Beijing time as the scheduling reference and provides conversion guidance without first asking for the user's locale or system timezone. This can cause cron schedules to be generated for the wrong timezone, leading to mistimed monitoring, missed reminders, or checks executing at unintended hours.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.