Back to skill

Security audit

Openclaw Team Builder

Security checks across malware telemetry and agentic risk

Overview

This is a Markdown-only team orchestration skill, but it includes high-impact live trading and autonomous configuration-change guidance without clear approval limits.

Install only if you intend to use this as a high-trust orchestration guide. Treat it as planning-only by default, review referenced agent files before activation, and do not connect it to live trading, paid generation, session control, or write APIs unless you add explicit approvals, dry-run defaults, spending/risk limits, audit logging, and rollback controls.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (11)

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The file materially expands the skill from team composition into operational execution: live trading, image/video generation, and engineering workflow orchestration. That scope mismatch is dangerous because a caller selecting a seemingly harmless team-building skill could indirectly trigger higher-risk actions and delegated execution paths not justified by the declared purpose.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
Documenting live market data access, trade execution, position management, and bot control inside a team-builder skill creates a serious hidden-capability risk. If invoked under the assumption it only assembles teams, the skill could expose or enable financially sensitive actions with real-world consequences, making the context more dangerous rather than less because trading is a high-impact domain.

Context-Inappropriate Capability

Medium
Confidence
87% confidence
Finding
Image and video generation are outside the declared scope of composing and activating teams, so embedding those capabilities creates unnecessary privilege and expectation mismatch. While less severe than trading, this can still lead to unauthorized content generation, unexpected cost incurrence, and indirect data handling through media workflows.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
This documentation expands the skill from team composition into autonomous strategy optimization and promotion of winning trading configurations to live systems. In a skill whose stated purpose is team discovery/composition, describing live trading changes creates a dangerous capability mismatch that could lead users or agents to take financially impactful actions outside expected scope.

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The file claims the methodology applies broadly to trading, image analysis, prompt engineering, configuration tuning, and data processing, which materially exceeds the declared team-builder scope. This kind of scope drift is dangerous because it normalizes autonomous experimentation in unrelated domains and may cause downstream agents to assume broader authority than users granted.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
The documentation explicitly describes autonomously modifying strategy parameters and promoting winning configurations to live systems via a write API. That is a high-risk operational capability with direct financial consequences, and it is unjustified by the stated purpose of a team-builder skill.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill explicitly says it can be used for "any job, project, or request," which creates an unbounded activation scope. In an agentic system, this can cause inappropriate delegation into domains requiring safety, authorization, or policy checks, increasing the chance the skill is invoked for sensitive or harmful tasks without adequate constraints.

Vague Triggers

Medium
Confidence
90% confidence
Finding
Claiming the skill can compose teams for "any job" overstates capability and omits negative examples or hard boundaries. That broad framing can encourage downstream agents to treat the skill as universally applicable, leading to misuse in high-risk contexts such as legal, financial, medical, or security-sensitive workflows.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The file explicitly instructs users to activate any specialist by reading a referenced definition file and adopting that role, without constraining which agents may be invoked or under what trust conditions. In a multi-agent skill, this broad delegation can cause unsafe role adoption, unintended authority expansion, or prompt-injection propagation from downstream agent definition files.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The activation template uses generic placeholders and imperative wording that make it easy to invoke arbitrary agents with broad task, context, and reviewer parameters. Because it lacks negative examples, prohibited uses, and authorization boundaries, an attacker or confused user could steer the system into loading inappropriate agents or passing unsafe context into them.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
Referencing promotion of winning configurations to live systems without any warning, confirmation step, or safety constraints encourages unsafe execution of financial changes. In the trading context, omission of user consent and risk acknowledgement materially increases the chance of harmful or unauthorized live actions.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.