Back to skill

Security audit

Pest & Disease Tracker

Security checks across malware telemetry and agentic risk

Overview

This is a local garden pest and disease tracker with disclosed storage and export behavior, but users should treat its pesticide and fungicide recommendations as general guidance only.

Install only if you are comfortable storing garden problem notes, affected plants, severity, treatments, and effectiveness history locally in ~/.openclaw/workspace/pest_tracker_db.json. Before applying any pesticide or fungicide it suggests, verify the current product label, crop suitability, local regulations, protective equipment, child and pet precautions, and edible-crop or pre-harvest restrictions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The description includes broad trigger language such as 'Use when dealing with garden pests, plant diseases, or treatment planning' and 'Perfect for home gardeners and small farmers managing plant health,' which can cause the skill to be invoked in a wide range of ordinary gardening conversations. Over-broad invocation increases the chance the agent routes user requests into this skill unnecessarily, exposing users to unintended tool behavior or recommendations beyond what was explicitly requested.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The recommendation output presents pesticide/fungicide products and treatment methods as actionable guidance without prominently warning users to verify crop safety, label restrictions, re-entry/pre-harvest intervals, or local regulatory compliance. In a gardening context, users may apply inappropriate products to edible crops or misuse treatments, creating health, environmental, or legal risks even though the code itself does not execute dangerous operations.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.