Back to skill

Security audit

Build Discipline

Security checks across malware telemetry and agentic risk

Overview

This is a local habit-coaching skill with no executable code or network behavior; the main caveat is that it may store personal routine details and has broad activation phrases.

Safe to install as a local discipline coach. Before using it heavily, decide what personal habit or health-adjacent details you are comfortable tracking, and check how your OpenClaw environment lets you view or delete stored commitments and streak history.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger phrases are broad, generic expressions that could easily appear in normal conversation, increasing the chance the skill activates unintentionally. Because the skill claims to store commitments and reminders, accidental invocation could cause undesired state changes or capture personal habit data when the user did not explicitly intend to use this skill.

Shadow Command Trigger

Medium
Category
Trigger Abuse
Confidence
84% confidence
Finding
The trigger 'build discipline' begins with the built-in command word 'build', creating a shadowing/conflict risk with core platform functionality. This can cause ambiguous routing where users intending a built-in build action may invoke this skill instead, or vice versa, undermining expected command boundaries.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.