Back to skill

Security audit

Note Processor

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward local note analyzer that reads a documented research-notes file and prints requested summaries, keywords, searches, and topic lists.

Install only if you are comfortable with content from ~/.openclaw/workspace/research_db.json being shown in terminal output or agent transcripts. Avoid using it on notes containing secrets, credentials, sensitive personal data, or material you would not want copied into logs, screenshots, or shared files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Missing User Warnings

Low
Confidence
84% confidence
Finding
The skill explicitly processes and displays research notes, tags, timestamps, and previews, but it does not warn users that running commands or redirecting output can expose sensitive content and metadata in terminal history, logs, shared files, or screenshots. This is a real but low-severity information disclosure risk because the functionality is expected, yet the lack of disclosure may cause users to handle sensitive research data less carefully.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.